UCF STIG Viewer Logo

Applications providing malware and/or firewall protection must monitor inbound and outbound communications for unauthorized activities or conditions.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35118 SRG-APP-000283-AS-NA SV-46405r1_rule Medium
Description
Unusual/unauthorized activities or conditions include internal traffic indicating the presence of malicious code within an information system or propagating among system components, the unauthorized export of information, and signaling to an external information system. Evidence of malicious code is used to identify potentially compromised information systems or information system components. Examples of applications that provide monitoring capability for unusual/unauthorized activities include, but are not limited to, intrusion detection, anti-virus and malware. Application servers do not provide Antivirus or firewall protection. That is not their functionality.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43506r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-39670r1_fix)
The requirement is NA. No fix is required.