UCF STIG Viewer Logo

Maintenance and security patches are NOT approved by the local DAA prior to installation in the system


Overview

Finding ID Version Rule ID IA Controls Severity
V-8532 DSN17.05 SV-9029r1_rule ECSC-1 Medium
Description
Requirement: The IAO will ensure that maintenance and security patches that are applied to a system are approved by the local DAA before installation. All patches and new system software must be tested on non-production systems/hardware prior to use / installation to determine the effects that the new software will have on systems operations and security. Furthermore the local DAA responsible for personally accepting the risk of operating the system must be aware of these effects and approve their use if the risk of using the software is acceptable.
STIG Date
Defense Switched Network STIG 2015-01-02

Details

Check Text ( C-7374r1_chk )
Review current configuration files of effected devices to confirm compliance
Fix Text (F-8033r1_fix)
> Implement processes / procedures, generate documents, and/or adjust configuration(s) / architecture, as necessary to comply with policy.