SV-222516r508029_rule
V-222516
SRG-APP-000384
APSC-DV-001480
CAT II
10
Restrict application execution in accordance with the policy, terms, and conditions specified.
Review the application documentation and interview the application administrator to determine if policies, rules, or restrictions exist regarding application usage or terms which authorize the conditions of application use.
If the policy, terms, or conditions state there are no usage restrictions, this requirement is not applicable.
Interview the application administrator, review policy, terms, and conditions documents to determine what the terms and conditions of application usage are.
Have the application administrator demonstrate how the program execution is restricted in accordance with the policy terms and conditions. Typical methods include but are not limited to the use of Windows Group Policy, AppLocker, Software Restriction Policies, Java Security Manager, and Role-Based Access Control (RBAC).
If application requirements or policy documents specify application execution restriction requirements and the execution of the application or its subcomponents are not restricted in accordance with requirements or policy, this is a finding.
V-222516
False
APSC-DV-001480
Review the application documentation and interview the application administrator to determine if policies, rules, or restrictions exist regarding application usage or terms which authorize the conditions of application use.
If the policy, terms, or conditions state there are no usage restrictions, this requirement is not applicable.
Interview the application administrator, review policy, terms, and conditions documents to determine what the terms and conditions of application usage are.
Have the application administrator demonstrate how the program execution is restricted in accordance with the policy terms and conditions. Typical methods include but are not limited to the use of Windows Group Policy, AppLocker, Software Restriction Policies, Java Security Manager, and Role-Based Access Control (RBAC).
If application requirements or policy documents specify application execution restriction requirements and the execution of the application or its subcomponents are not restricted in accordance with requirements or policy, this is a finding.
M
4093