UCF STIG Viewer Logo

Application servers must prevent encrypted data from bypassing content-checking mechanisms.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35552 SRG-APP-000056-AS-NA SV-46839r1_rule Medium
Description
Information flow control regulates where information is allowed to travel within an information system and between information systems (as opposed to who is allowed to access the information), without explicit regard to subsequent access to that information. The AS itself does not transmit encrypted data. The AS provides the capability for hosted applications to transmit encrypted data. This is a hosted application requirement.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43891r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40092r1_fix)
The requirement is NA. No fix is required.