This F5 deployment guide provides guidance on using the F5 iApp for NIST SP-800-53r4 to configure a BIG-IP device to support security controls according to the U.S. National Institute of Standards and Technology (NIST) Special Publication 800-53 (Revision 4): Security and Privacy Controls for Federal Information Systems and Organizations (updated 01-02-2015).
NIST SP-800-53r4 is a complex document. Only some of the controls (that is, policies plus supporting technical measures) that organizations adopt to comply with SP-800-53r4 relate to the BIG-IP configuration. This deployment guide discusses the security controls in Appendix F of NIST SP-800-53r4 most applicable to BIG-IP configuration and shows how to support them.
This guide is about configuring the management features of the BIG-IP system rather than the network-traffic-processing modules of system such as BIG-IP Local Traffic Manager. In other words, this deployment guide helps you manage the BIG-IP system as an entity responsive to your SP-800-53r4 controls. Using BIG-IP as a tool to help control other entities like network-based applications is beyond the scope of this document.