SV-222627r508029_rule
V-222627
SRG-APP-000516
APSC-DV-002970
CAT II
10
Configure the application according to the product STIG or when a STIG is not available, utilize:
- commercially accepted practices,
- independent testing results, or
- vendor literature and lock down guides.
Review the application documentation to identify application name, features and version.
Identify if a DoD STIG or NSA guide is available.
If no STIG is available for the product, the application and application components must be configured by the following as available:
- commercially accepted practices,
- independent testing results, or
- vendor literature and lock down guides.
If the application and application components do not have DoD STIG or NSA guidance available and are not configured according to:
commercially accepted practices,
independent testing results,
or vendor literature and lock down guides, this is a finding.
V-222627
False
APSC-DV-002970
Review the application documentation to identify application name, features and version.
Identify if a DoD STIG or NSA guide is available.
If no STIG is available for the product, the application and application components must be configured by the following as available:
- commercially accepted practices,
- independent testing results, or
- vendor literature and lock down guides.
If the application and application components do not have DoD STIG or NSA guidance available and are not configured according to:
commercially accepted practices,
independent testing results,
or vendor literature and lock down guides, this is a finding.
M
4093