SV-222657r561287_rule
V-222657
SRG-APP-000516
APSC-DV-003236
CAT II
10
The development team creates an application incident response plan documenting and establishing a process that at a minimum:
- Tracks reported vulnerabilities and bugs
- Confirms reported vulnerabilities and bugs
- Tracks remediation effort
- Notifies application users of available updates that address the reported issues.
If the application is a COTS application and the development team is not accessible to interview this requirement is not applicable.
Interview the application development team members. Request and review the application incident response plan.
Ensure the plan includes an implemented process that:
- Tracks reported vulnerabilities and bugs
- Confirms reported vulnerabilities and bugs
- Tracks remediation effort
- Notifies application users of available updates that address the reported issues.
If the application incident response plan does not exist and at a minimum does not implement the aforementioned processes, this is a finding.
V-222657
False
APSC-DV-003236
If the application is a COTS application and the development team is not accessible to interview this requirement is not applicable.
Interview the application development team members. Request and review the application incident response plan.
Ensure the plan includes an implemented process that:
- Tracks reported vulnerabilities and bugs
- Confirms reported vulnerabilities and bugs
- Tracks remediation effort
- Notifies application users of available updates that address the reported issues.
If the application incident response plan does not exist and at a minimum does not implement the aforementioned processes, this is a finding.
M
4093