UCF STIG Viewer Logo

The application must enforce Discretionary Access Control (DAC) policy allowing users to specify and control sharing by named individuals, groups of individuals, or by both, limiting propagation of access rights, and including or excluding access to the g


Overview

Finding ID Version Rule ID IA Controls Severity
V-35484 SRG-APP-000036-AS-NA SV-46771r1_rule Medium
Description
Access control policies (e.g., identity-based policies, role-based policies, attribute-based policies) and access enforcement mechanisms (e.g., access control lists, access control matrices, cryptography) are employed by organizations to control access between users (or processes acting on behalf of users) and objects (e.g., devices, files, records, processes, programs, domains). DAC is a type of access control methodology serving as a means of restricting access to objects and data based on the identity of subjects and/or groups to which they belong. It is discretionary in the sense that application users with the appropriate permissions to access an application resource or data have the discretion to pass that permission on to another user either directly or indirectly. The AS utilizes RBAC and does not allow individual users to specify or control sharing of AS objects.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43837r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40025r1_fix)
The requirement is NA. No fix is required.