STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 23 Oct 2020:

The application must provide notifications or alerts when product update and security related patches are available.

DISA Rule

SV-222670r508029_rule

Vulnerability Number

V-222670

Group Title

SRG-APP-000516

Rule Version

APSC-DV-003345

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Provide a distribution mechanism for obtaining updates to the application.

Include a description of the issue, a summary of risk as well as potential mitigations and how to obtain the update.

Check Contents

Review the components of the application. Interview the application administrator.

Have the application administrator demonstrate the application notification process that occurs when a security patch or product update is available.

The process must include a brief description of the issue and any potential risks related to the issue.

The process must also include information regarding the availability of the patch or update and how it can be obtained as well as any potential mitigations that can be utilized in the interim.

If there is no application security patch or update notification process, this is a finding.

If the application notification process does not include a brief description, information on risks, how to obtain the patch or update and any potential mitigations, this is a finding.

Vulnerability Number

V-222670

Documentable

False

Rule Version

APSC-DV-003345

Severity Override Guidance

Review the components of the application. Interview the application administrator.

Have the application administrator demonstrate the application notification process that occurs when a security patch or product update is available.

The process must include a brief description of the issue and any potential risks related to the issue.

The process must also include information regarding the availability of the patch or update and how it can be obtained as well as any potential mitigations that can be utilized in the interim.

If there is no application security patch or update notification process, this is a finding.

If the application notification process does not include a brief description, information on risks, how to obtain the patch or update and any potential mitigations, this is a finding.

Check Content Reference

M

Target Key

4093

Comments