SV-222514r508029_rule
V-222514
SRG-APP-000133
APSC-DV-001440
CAT II
10
Configure the application OS file permissions to restrict access to software libraries and configure the application to restrict user access regarding software library update functionality to only authorized users or processes.
Review the application documentation and interview the application administrator to identify the application architecture.
Identify application folders where application libraries are stored.
Review permissions of application folders and library files contained with the folders to ensure file permissions restrict access to authorized users or processes.
Access application configuration settings.
Examine settings for capability to update software libraries or extend application functionality via the application.
Review user roles and access rights within the application to determine if access to this capability is restricted to authorized users.
If file restrictions do not limit write access to library files and if the application does not restrict access to library update functionality, this is a finding.
V-222514
False
APSC-DV-001440
Review the application documentation and interview the application administrator to identify the application architecture.
Identify application folders where application libraries are stored.
Review permissions of application folders and library files contained with the folders to ensure file permissions restrict access to authorized users or processes.
Access application configuration settings.
Examine settings for capability to update software libraries or extend application functionality via the application.
Review user roles and access rights within the application to determine if access to this capability is restricted to authorized users.
If file restrictions do not limit write access to library files and if the application does not restrict access to library update functionality, this is a finding.
M
4093