UCF STIG Viewer Logo

Applications must maintain reviewer/releaser identity and credentials within the established chain of custody for all information reviewed or released.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36274 SRG-APP-083-NA SV-47678r1_rule Medium
Description
Non-repudiation protects individuals against later claims by an author of not having authored a particular document, a sender of not having transmitted a message, a receiver of not having received a message, or a signatory of not having signed a document. Non-repudiation services can be used to determine if information originated from an individual, or if an individual took specific actions (e.g., sending an email, signing a contract, approving a procurement request) or received specific information. Non-repudiation services are obtained by employing various techniques or mechanisms (e.g., digital signatures, digital message receipts). Rationale for non-applicability: The MDM server is not intended to store user data and therefore would not employ notions of chain of custody.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44514r1_chk )
This requirement is NA for the MDM server SRG.
Fix Text (F-40805r1_fix)
The requirement is NA. No fix is required.