SV-222620r508029_rule
V-222620
SRG-APP-000516
APSC-DV-002890
CAT I
10
Separate web server from other application tiers and place it on a separate network segment apart from the application and database servers in accordance with DoD DMZ data access controls requirements.
Review the application documentation.
Review the application data protection requirements and identify if all data types hosted on server are identical.
Review the network diagram and identify web servers/web services, web application servers, and database servers.
If the application is not hosted in the DoD DMZ, this requirement is not applicable.
Verify the application web servers are separated from the application and database servers if the application is a tiered design as per DoD DMZ STIG requirements.
If the application is tiered and the network infrastructure hosting the application is not configured to provide separation and security access controls between the tiered layers in accordance with DoD DMZ requirements, this is a finding.
V-222620
False
APSC-DV-002890
Review the application documentation.
Review the application data protection requirements and identify if all data types hosted on server are identical.
Review the network diagram and identify web servers/web services, web application servers, and database servers.
If the application is not hosted in the DoD DMZ, this requirement is not applicable.
Verify the application web servers are separated from the application and database servers if the application is a tiered design as per DoD DMZ STIG requirements.
If the application is tiered and the network infrastructure hosting the application is not configured to provide separation and security access controls between the tiered layers in accordance with DoD DMZ requirements, this is a finding.
M
4093