Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35569 | SRG-APP-000084-AS-NA | SV-46856r1_rule | Medium |
Description |
---|
This non-repudiation control enhancement is intended to mitigate the risk that information could be modified between review and transfer/release particularly when transfer is occurring between security domains. In those instances where the application is transferring data intended for release across security domains, the application must validate the binding of the reviewer's identity to the information at the transfer/release point prior to transfer/release from one security domain to another security domain. The application server itself is not designed to produce or release information and therefore does not employ notions of chain of custody. This requirement relates to applications that are designed to output data. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43909r1_chk ) |
---|
This requirement is NA for the AS SRG. |
Fix Text (F-40110r1_fix) |
---|
The requirement is NA. No fix is required. |