SV-222631r508029_rule
V-222631
SRG-APP-000516
APSC-DV-003000
CAT II
10
Review access privileges to the CM repository at least every three months.
Review the application system documentation.
Interview the application administrator.
Identify if development of the application is done in house and if application configuration management repository exists.
If application development is not done in house and if a code configuration management repository does not exist, the requirement is not applicable.
Review CM management processes and procedures.
Verify the CM repository access permissions are reviewed at least every three months.
Ask the application administrator or the CM administrator when the last time the CM access privileges were reviewed.
If CM access privileges have not been reviewed within the last three months, this is a finding.
V-222631
False
APSC-DV-003000
Review the application system documentation.
Interview the application administrator.
Identify if development of the application is done in house and if application configuration management repository exists.
If application development is not done in house and if a code configuration management repository does not exist, the requirement is not applicable.
Review CM management processes and procedures.
Verify the CM repository access permissions are reviewed at least every three months.
Ask the application administrator or the CM administrator when the last time the CM access privileges were reviewed.
If CM access privileges have not been reviewed within the last three months, this is a finding.
M
4093