Riverbed NetIM Y25M09 Checklist Details (Checklist Revisions)
Supporting Resources:
-
Download Standalone XCCDF 1.1.4 - Riverbed NetIM STIG
- Defense Information Systems Agency
Target:
| Target | CPE Name |
|---|---|
| Riverbed NetIM | cpe:/a:riverbed:netim:- (View CVEs) |
Checklist Highlights
- Checklist Name:
- Riverbed NetIM
- Checklist ID:
- 1318
- Version:
- Y25M09
- Type:
- Compliance
- Review Status:
- Candidate
- Authority:
- Governmental Authority: Defense Information Systems Agency
- Original Publication Date:
- 01/07/2026
Checklist Summary:
The Riverbed NetIM Security Technical Implementation Guide (STIG) provides security policy and technical configuration requirements for the use of the Riverbed SteelCentral NetIM appliances in the Department of Defense (DOD). Riverbed NetIM is a network monitoring and troubleshooting tool that provides visibility into IT infrastructure by mapping network topology, detecting performance issues, tracking configuration changes, mapping application network paths, and allowing users to diagnose network problems through detailed diagrams. Key functions of Riverbed NetIM: • Network discovery and mapping: Automatically discovers network devices and their connections to create a visual representation of the network topology. • Performance monitoring: Tracks key network metrics like bandwidth utilization, packet loss, latency, and CPU usage to identify performance bottlenecks. • Application path mapping: Identifies the network path traversed by specific applications to pinpoint performance issues related to application delivery. • Configuration management: Tracks changes in device configurations and alerts users to potential issues arising from configuration modifications. • Troubleshooting tools: Provides features like packet capture and analysis to diagnose network connectivity issues. • Alerting and reporting: Generates alerts based on predefined thresholds and provides detailed reports on network performance and health. To provide these functions, NetIM can login to network devices. Thus, securing the operating system, management interfaces, and network communications is imperative. The Riverbed NetIM STIG covers both the Ubuntu operating system and the NetIM application management functions. Requirements for configuring the reporting, traffic analysis, or workflow configuration functions is out of scope but must be specified in the site’s System Security Plan (SSP) and configuration documentation.
Checklist Role:
- Web Application Server
Known Issues:
Not provided.
Target Audience:
Parties within the DOD and federal government’s computing environments can obtain the applicable STIG from the DOD Cyber Exchange website at https://cyber.mil/. This site contains the latest copies of STIGs, SRGs, and other related security information. Those without a Common Access Card (CAC) that has DOD Certificates can obtain the STIG from https://public.cyber.mil/.
Target Operational Environment:
- Managed
- Specialized Security-Limited Functionality (SSLF)
Testing Information:
Not provided.
Regulatory Compliance:
DODI 8500.01
Comments/Warnings/Miscellaneous:
Comments or proposed revisions to this document should be sent via email to the following address: [email protected]. DISA will coordinate all change requests with the relevant DOD organizations before inclusion in this document. Approved changes will be made in accordance with the DISA maintenance release schedule.
Disclaimer:
Not provided.
Product Support:
Not provided.
Point of Contact:
Sponsor:
Not provided.
Licensing:
Not provided.
Change History:
Created New Checklist - 01/07/2026
Dependency/Requirements:
| URL | Description |
|---|
References:
| Reference URL | Description |
|---|
NIST checklist record last modified on 01/07/2026
* This checklist is still undergoing review for inclusion into the NCP.
