Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-16838 | APP6070 | SV-17838r1_rule | DCSD-1 | Low |
Description |
---|
When maintenance no longer exists for an application, there are no individuals responsible for making security updates. The application should maintain procedures for decommissioning. |
STIG | Date |
---|---|
Application Security and Development Checklist | 2014-01-07 |
Check Text ( C-17844r1_chk ) |
---|
Interview the application representative to determine if provisions are in place to notify users when an application is decommissioned. 1) If provisions are not in place to notify users when an application is decommissioned, it is a finding. |
Fix Text (F-17158r1_fix) |
---|
Create and establish procedures to notify users when an application is decommissioned. |