Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000190-IDPS-000201 | SRG-NET-000190-IDPS-000201 | SRG-NET-000190-IDPS-000201_rule | Medium |
Description |
---|
The purpose of this control is to prevent information produced by the actions of a prior user, role, or the actions of a process acting on behalf of a prior user/role from being available to any current user, role, or current process obtaining access to a shared system resource (e.g., registers, main memory, secondary storage) after the resource has been released back to the IDPS. Control of information in shared resources is also referred to as object reuse. |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43355_chk ) |
---|
Verify the application is designed to prevent unauthorized and unintended information transfer between user sessions. Settings needed to enable or optimize this security feature must be enabled and configured. If the system is not configured to prevent unauthorized and unintended information transfer via shared system resources, this is a finding. |
Fix Text (F-43355_fix) |
---|
Enable settings that prevent unauthorized and unintended information transfer via shared system resources. |