Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-39433 | ENTD0030 | SV-51291r1_rule | VIVM-1 | Medium |
Description |
---|
An asset management system is used to send out notifications on vulnerabilities in commercial and military information infrastructures as they are discovered. If the organization's assets are not registered with an asset management system, administrators will not be notified of important vulnerabilities such as viruses, denial of service attacks, system weaknesses, back doors, and other potentially harmful situations. Additionally, there will be no way to enter, track, or resolve findings during a review. |
STIG | Date |
---|---|
Test and Development Zone C Security Technical Implementation Guide | 2015-12-17 |
Check Text ( C-46812r1_chk ) |
---|
Determine whether all systems and network infrastructure devices supporting the test and development environment are registered in an asset management system. If any systems and network infrastructure devices supporting the test and development environment are not registered in an asset management system, this is a finding. |
Fix Text (F-44446r2_fix) |
---|
Register the network infrastructure and systems supporting the test and development environment in a DoD asset management program. |