UCF STIG Viewer Logo

The application server must validate the binding of the reviewers identity to the information at the transfer/release point prior to transfer/release from one security domain to another security domain.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35569 SRG-APP-000084-AS-NA SV-46856r1_rule Medium
Description
This non-repudiation control enhancement is intended to mitigate the risk that information could be modified between review and transfer/release particularly when transfer is occurring between security domains. In those instances where the application is transferring data intended for release across security domains, the application must validate the binding of the reviewer's identity to the information at the transfer/release point prior to transfer/release from one security domain to another security domain. The application server itself is not designed to produce or release information and therefore does not employ notions of chain of custody. This requirement relates to applications that are designed to output data.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43909r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40110r1_fix)
The requirement is NA. No fix is required.