SV-222400r508029_rule
V-222400
SRG-APP-000014
APSC-DV-000200
CAT I
10
Design and configure the application to use validity periods, ensure validity periods are verified on all WS-Security token profiles and SAML Assertions.
Ask the application representative for the design document.
Review the design document for web services.
If the application does not utilize WSS or SAML assertions, this requirement is not applicable.
Review the design document and verify validity periods are checked on all messages using WS-Security or SAML assertions.
If the design document does not exist, or does not indicate validity periods are checked on messages using WS-Security or SAML assertions, this is a finding.
V-222400
False
APSC-DV-000200
Ask the application representative for the design document.
Review the design document for web services.
If the application does not utilize WSS or SAML assertions, this requirement is not applicable.
Review the design document and verify validity periods are checked on all messages using WS-Security or SAML assertions.
If the design document does not exist, or does not indicate validity periods are checked on messages using WS-Security or SAML assertions, this is a finding.
M
4093