SV-222596r508029_rule
V-222596
SRG-APP-000439
APSC-DV-002440
CAT I
10
Configure all of the application systems to require TLS encryption in accordance with data protection requirements.
Review the application documentation and interview the application administrator.
Identify application clients, servers and associated network connections including application networking ports.
Identify the types of data processed by the application and review any documented data protection requirements.
Identify the application communication protocols.
Review application documents for instructions or guidance on configuring application encryption settings.
Verify the application is configured to enable encryption protections for data in accordance with the data protection requirements. If no data protection requirements exist, ensure all application data is encrypted.
If the application does not utilize TLS, IPsec or other approved encryption mechanism to protect the confidentiality and integrity of transmitted information, this is a finding.
V-222596
False
APSC-DV-002440
Review the application documentation and interview the application administrator.
Identify application clients, servers and associated network connections including application networking ports.
Identify the types of data processed by the application and review any documented data protection requirements.
Identify the application communication protocols.
Review application documents for instructions or guidance on configuring application encryption settings.
Verify the application is configured to enable encryption protections for data in accordance with the data protection requirements. If no data protection requirements exist, ensure all application data is encrypted.
If the application does not utilize TLS, IPsec or other approved encryption mechanism to protect the confidentiality and integrity of transmitted information, this is a finding.
M
4093