| Vuln ID | Severity | Asset | STIG | Title | Status | Doc Status | Assigned To | Actions |
|---|---|---|---|---|---|---|---|---|
| V-206641 | CAT II | MONT-DB-002 | Database Security Requirements Guide | The DBMS must implement NIST FIPS 140-2 or 140-3 v... | - | |||
Check TextVerify the DBMS implements NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements. If the DBMS does not implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements, this is a finding. Fix TextConfigure the DBMS to implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements. CommentsThe DBMS is configured to start in FIPS mode using the -fips database server option (SQL Anywhere 17 - -fips Database Option.pdf). This option enables the DBMS to utilize NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owner’s requirements.
Source: Montford Point ShipCLIP DB V4R4.ckl
Scan Date: 2026-03-06T12:50:21.809591
Technology Area: Database Review
|
||||||||