Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35610 | SRG-APP-000200-AS-NA | SV-46897r1_rule | Medium |
Description |
---|
The need to verify security functionality applies to all security functions. For those security functions not able to execute automated self-tests the organization either implements compensating security controls or explicitly accepts the risk of not performing the verification as required. Information system transitional states include, startup, restart, shutdown, and abort. This requirement is NA. It relates to functional testing of security specifications conducted during application development as an overall development process. This activity is not conducted on any production system including application servers. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43953r1_chk ) |
---|
This requirement is NA for the AS SRG. |
Fix Text (F-40151r1_fix) |
---|
The requirement is NA. No fix is required. |