STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 23 Oct 2020:

Test procedures must be created and at least annually executed to ensure system initialization, shutdown, and aborts are configured to verify the system remains in a secure state.

DISA Rule

SV-222647r508029_rule

Vulnerability Number

V-222647

Group Title

SRG-APP-000516

Rule Version

APSC-DV-003160

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Create test procedures to test the security state of the application and exercise test procedures annually.

Check Contents

Review the process documentation and interview the admin staff.

Identify if testing procedures exist and if they include annual testing to ensure the application remains in a secure state on initialization, shutdown, and aborts.

Checks should include at a minimum, attempts to access the application and application configuration settings without credentials or with improper credentials both locally and remotely.

Dates should be noted as to the last date of testing.

If annual testing procedures do not exist, or if administrators are unable to provide testing dates that indicate the tests were conducted within the last year, this is a finding.

Vulnerability Number

V-222647

Documentable

False

Rule Version

APSC-DV-003160

Severity Override Guidance

Review the process documentation and interview the admin staff.

Identify if testing procedures exist and if they include annual testing to ensure the application remains in a secure state on initialization, shutdown, and aborts.

Checks should include at a minimum, attempts to access the application and application configuration settings without credentials or with improper credentials both locally and remotely.

Dates should be noted as to the last date of testing.

If annual testing procedures do not exist, or if administrators are unable to provide testing dates that indicate the tests were conducted within the last year, this is a finding.

Check Content Reference

M

Target Key

4093

Comments