UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application server must automatically implement safeguards and countermeasures if security functions (or mechanisms) are changed inappropriately.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35225 SRG-APP-000134-AS-000093 SV-46512r1_rule Medium
Description
Any changes to the components of the AS can potentially have significant effects on the overall security of the system. In order to ensure a prompt response to failed application installations and AS upgrades, the AS must provide an automated rollback capability that allows the system to be restored to a previous known good configuration state prior to the application installation or AS upgrade.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43597r1_chk )
Check the AS documentation and configuration to determine if the AS provides an automated rollback capability. The rollback capability can be manually invoked or scripted. If the AS is not configured to meet this requirement, this is a finding.
Fix Text (F-39771r1_fix)
Configure the AS to rollback failed application installations and AS upgrades.