Dod Kvm User Agreement

If the KVM switch configuration can be protected by a password, including user ID and password combinations or PKI for network-connected switches, create a DOD-enabled password to protect the configuration. If the KVM switch configuration cannot be password protected, including user ID/password or PKI combinations for network-connected switches, replace it with a KVM switch that either has no configuration or the configuration can be password protected. Users who access ISSs to which they do not need access can compromise sensitive data. The ISSO ensures that the KVM switch is configured to restrict a user`s access to only the systems they need. All peripheral devices that are not connected to a KVM switch must be used regardless of the current configuration of the KVM switch. This device can contain persistent memory that can be used to move data between ISs of different classification levels, affecting either the data being moved and the IS to which the data was moved. When the KVM switch is connected to different classification levels, the ISSO, SA, and user ensure that no devices other than the keyboard, video, or mouse are connected to the KVM. The expert will interview the ISSO and consult the SFUG or equivalent documentation to verify if the following points are discussed. 1. A/B switches should only be used if there is no other solution. 2. A/B switches should only be used to connect multiple devices to a single Daesh.

3. A/B switches should never be used to connect a single device to multiple ISs. 4. When an A/B switch is used to connect or release devices between two or more IS, the ISs shall be intended for use by a single user in the user`s work area and be visible from all connected systems. If there is no documentation with the SFUG that describes the correct use of an A/B switch and the user`s responsibilities, this is a result. A written user agreement allows the ISSO to be sure that the end user who will use the device has received documentation that explains their duties and responsibilities with respect to the device, and has confirmed that they have read and understood the documentation....