UCF STIG Viewer Logo

The application server must isolate security functions from non-security functions by means of an isolation boundary (implemented via partitions and domains) controlling access to, and protecting the integrity of software.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35428 SRG-APP-000233-AS-NA SV-46715r1_rule Medium
Description
Developers and implementers can increase the assurance in security functions by employing well-defined security policy models; structured, disciplined, and rigorous hardware and software development techniques; and sound system/security engineering principles. Separation and isolation is met through application virtualization. Isolated applications contain their own security functionality within the application layer. CCI-001087 requires application isolation and virtualization within the application server itself. This requirement will apply to the applications residing on top of the AS, but not the AS itself.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43779r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-39972r1_fix)
The requirement is NA. No fix is required.