STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← AC-4 (8) — Information Flow Enforcement

CCI-000032

Definition

Enforce information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows.

Parent Control

AC-4 (8)Information Flow EnforcementAccess Control

Linked STIG Checks (19)

V-204918CAT IIThe ALG that is part of a CDS must enforce information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows.Application Layer Gateway Security Requirements GuideV-255992CAT IIIThe Arista BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Arista MLS EOS 4.2x Router Security Technical Implementation GuideV-255996CAT IIIThe Arista BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Arista MLS EOS 4.2x Router Security Technical Implementation GuideV-255992CAT IIIThe Arista BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Arista MLS EOS 4.X Router Security Technical Implementation GuideV-255996CAT IIIThe Arista BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Arista MLS EOS 4.X Router Security Technical Implementation GuideV-216602CAT IIIThe Cisco BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Cisco IOS Router RTR Security Technical Implementation GuideV-216603CAT IIIThe Cisco BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Cisco IOS Router RTR Security Technical Implementation GuideV-216692CAT IIIThe Cisco BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Cisco IOS XE Router RTR Security Technical Implementation GuideV-216693CAT IIIThe Cisco BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Cisco IOS XE Router RTR Security Technical Implementation GuideV-221028CAT IIIThe Cisco BGP switch must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Cisco IOS XE Switch RTR Security Technical Implementation GuideV-221029CAT IIIThe Cisco BGP switch must be configured to reject route advertisements from CE switches with an originating AS in the AS_PATH attribute that does not belong to that customer.Cisco IOS XE Switch RTR Security Technical Implementation GuideV-216782CAT IIIThe Cisco BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Cisco IOS XR Router RTR Security Technical Implementation GuideV-216783CAT IIIThe Cisco BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Cisco IOS XR Router RTR Security Technical Implementation GuideV-221108CAT IIIThe Cisco BGP switch must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Cisco NX OS Switch RTR Security Technical Implementation GuideV-221109CAT IIIThe Cisco BGP switch must be configured to reject route advertisements from CE switches with an originating AS in the AS_PATH attribute that does not belong to that customer.Cisco NX OS Switch RTR Security Technical Implementation GuideV-253978CAT IIIThe Juniper BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Juniper EX Series Switches Router Security Technical Implementation GuideV-253982CAT IIIThe Juniper router configured for BGP must reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Juniper EX Series Switches Router Security Technical Implementation GuideV-217058CAT IIIThe Juniper BGP router must be configured to reject route advertisements from BGP peers that do not list their autonomous system (AS) number as the first AS in the AS_PATH attribute.Juniper Router RTR Security Technical Implementation GuideV-217059CAT IIIThe Juniper BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.Juniper Router RTR Security Technical Implementation Guide