UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application server must provide notification of failed automated security tests.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35686 SRG-APP-000275-AS-NA SV-46973r1_rule Medium
Description
The need to verify security functionality applies to all security functions. For those security functions not able to execute automated self-tests, the organization either implements compensating security controls or explicitly accepts the risk of not performing the verification as required. Information system transitional states include startup, restart, shutdown, and abort. This requirement relates to functional testing of security specifications conducted during the vendor's development of the application server itself. There is no way to test for this on a deployed system. The requirement is NA.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-44028r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40228r1_fix)
The requirement is NA. No fix is required.