UCF STIG Viewer Logo

The application server must separate hosted application functionality from AS management functionality.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35376 SRG-APP-000211-AS-000146 SV-46663r1_rule Medium
Description
Application server management functionality includes functions necessary to administer the application server, and requires privileged access via one of the accounts assigned to a management role. The separation of AS administration functionality from hosted application functionality is either physical or logical and is accomplished by using different computers, different central processing units, different instances of the operating system, network addresses, network ports, or combinations of these methods, as appropriate.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43739r1_chk )
Review the AS documentation and configuration to verify that the AS separates admin functionality from hosted application functionality. If the AS does not separate AS admin functionality from hosted application functionality, this is a finding.
Fix Text (F-39923r1_fix)
Configure the AS so that admin management functionality and hosted applications are separated.