UCF STIG Viewer Logo

The application must protect information obtained from intrusion monitoring tools from unauthorized access, modification, and deletion.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35108 SRG-APP-000288-AS-NA SV-46395r1_rule Medium
Description
Intrusion monitoring applications are, by their nature, designed to monitor and record network and system traffic and activity. They can accumulate a significant amount of sensitive data, examples of which could include user account information and application data not related to the intrusion monitoring application itself. Intrusion monitoring tools also obtain information that is critical to conducting forensic analysis on attacks occurring within the network. This data may be sensitive in nature. Information obtained by intrusion monitoring applications in the course of evaluating network and system security needs to be protected. The AS is not an information system monitoring tool. This requirement is NA.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43496r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-39660r1_fix)
The requirement is NA. No fix is required.