SV-222624r508029_rule
V-222624
SRG-APP-000516
APSC-DV-002930
CAT II
10
Perform active vulnerability and fuzz testing of the application.
Verify the vulnerability scanning tool is configured to test all application components and functionality.
Address discovered vulnerabilities.
Ask the application representative to provide vulnerability test procedures and vulnerability test results.
Ask the application representative to provide the settings that were used to conduct the vulnerability testing.
Verify the automated vulnerability scanning tool was appropriately configured to assure as complete a test as possible of the application architecture components. E.g., if the application includes a web server, web server tests must be included.
If the vulnerability scan report includes informational and/or non-critical results this is not a finding.
If previously identified vulnerabilities have subsequently been resolved, this is not a finding.
If the application test procedures and test results do not include active vulnerability and fuzz testing this is a finding.
If the vulnerability scan results include critical vulnerabilities, this is a finding.
If the vulnerability scanning tests are not relevant to the architecture of the application, this is a finding.
V-222624
False
APSC-DV-002930
Ask the application representative to provide vulnerability test procedures and vulnerability test results.
Ask the application representative to provide the settings that were used to conduct the vulnerability testing.
Verify the automated vulnerability scanning tool was appropriately configured to assure as complete a test as possible of the application architecture components. E.g., if the application includes a web server, web server tests must be included.
If the vulnerability scan report includes informational and/or non-critical results this is not a finding.
If previously identified vulnerabilities have subsequently been resolved, this is not a finding.
If the application test procedures and test results do not include active vulnerability and fuzz testing this is a finding.
If the vulnerability scan results include critical vulnerabilities, this is a finding.
If the vulnerability scanning tests are not relevant to the architecture of the application, this is a finding.
M
4093