UCF STIG Viewer Logo

The application server management interface must retain the system use notification message or banner on the screen until users take explicit actions to logon for further access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35098 SRG-APP-000069-AS-000036 SV-46385r1_rule Low
Description
To establish acceptance of system usage policy, a click-through banner at application server logon is required. The banner shall prevent further activity on the application server unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK". The text of this banner should be customizable in the event of future user agreement changes.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43486r2_chk )
Review AS product documentation and configuration to determine that the logon banner can be displayed until the user takes action to acknowledge the agreement.

If the banner screen allows continuation on to the logon screen without user interaction, this is a finding.
Fix Text (F-39650r2_fix)
Configure the AS to retain the logon banner on the screen until the user takes explicit actions to logon to the server.