SV-222511r508029_rule
V-222511
SRG-APP-000380
APSC-DV-001410
CAT II
10
Configure the application to limit access to configuration settings to only authorized users.
Review the application documentation and configuration settings.
Access the application configuration settings interface as a regular non-privileged user. Attempt to make configuration changes to the application.
If configuration changes can be made by regular non-privileged users, this is a finding.
Review the locations of all configuration files used by the application.
Examine the file permission settings and determine who has access to the configuration files.
If access permissions to configuration files are not restricted to application administrators, this is a finding.
V-222511
False
APSC-DV-001410
Review the application documentation and configuration settings.
Access the application configuration settings interface as a regular non-privileged user. Attempt to make configuration changes to the application.
If configuration changes can be made by regular non-privileged users, this is a finding.
Review the locations of all configuration files used by the application.
Examine the file permission settings and determine who has access to the configuration files.
If access permissions to configuration files are not restricted to application administrators, this is a finding.
M
4093