UCF STIG Viewer Logo

The application must ensure the acquisition of mobile code to be deployed in information systems meets organization-defined mobile code requirements.


Overview

Finding ID Version Rule ID IA Controls Severity
V-30596 SRG-APP-NA SV-40347r1_rule Medium
Description
Decisions regarding the acquisition of mobile code within organizational information systems need to include evaluations that determine the potential for the code to cause damage to the system if used maliciously. Mobile code technologies include, for example, Java, JavaScript, ActiveX, PDF, Postscript, Shockwave movies, Flash animations, and VBScript. Usage restrictions and implementation guidance apply to both the selection and use of mobile code installed on organizational servers and mobile code downloaded and executed on individual workstations. DoDI 8552.01 policy pertains to the use of mobile code technologies within DoD information systems. Mobile code that is acquired for use and deployment in DoD information systems must meet DoD policy requirements This requirement relates to the acquisition of mobile code. The purpose is to ensure DoD organizations review applications which utilize mobile code to ensure they adhere to DoD mobile code policy prior to acquiring these applications and introducing them into the DoD environment. This is not an application specific requirement and is Not Applicable to applications.
STIG Date
Application Security Requirements Guide 2011-12-28

Details

Check Text ( None )
None
Fix Text (None)
None