UCF STIG Viewer Logo

The Mainframe Product must prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code run-time environments, and mobile agent systems.


Overview

Finding ID Version Rule ID IA Controls Severity
V-205516 SRG-APP-000210-MFP-000281 SV-205516r397708_rule Medium
Description
Mobile code can cause damage to the system. It can execute without explicit action from, or notification to, a user. Preventing automatic execution of mobile code includes, for example, disabling auto execute features on information system components. This requirement applies to mobile code-enabled software, which is capable of executing one or more types of mobile code.
STIG Date
Mainframe Product Security Requirements Guide 2022-09-22

Details

Check Text ( C-5782r299781_chk )
If the Mainframe Product has no function or capability for mobile code use, this is not applicable.

Examine installation and configuration settings.

If the Mainframe Product is not configured to prevent the automatic execution of mobile code in all applications, this is a finding.
Fix Text (F-5782r299782_fix)
Configure the Mainframe Product to prevent the automatic execution of mobile code in all applications.