SV-76943r1_rule
V-62453
SRG-APP-000156-AS-000106
CF11-04-000129
CAT II
10
If web services are not published, this finding is not applicable.
If web services are published, but the SOAP protocol is not used, this finding is not applicable.
If web services are published and the SOAP protocol is used to access data, but the data is not sensitive, this finding is not applicable.
Install the ws-security suite to secure access to sensitive data.
Determine if web services are published using the SOAP protocol to access sensitive data. This may be determined by interviewing the administrator or by reviewing hosted applications code, hosted application design documentation, published web services design documentation or ColdFusion baseline documentation.
If web services are not published, this finding is not applicable.
If web services are published, but the SOAP protocol is not used, this finding is not applicable.
If web services are published and the SOAP protocol is used to access data, but the data is not sensitive, this finding is not applicable.
Determine if the ws-security suite is in place to provide secure authentication to the sensitive data by interviewing the administrator or by reviewing hosted applications code, hosted application design documentation, published web services design documentation or ColdFusion baseline documentation.
If web services are published using the SOAP protocol to access sensitive data and the ws-security suite is not used to secure the access, this is a finding.
V-62453
False
CF11-04-000129
Determine if web services are published using the SOAP protocol to access sensitive data. This may be determined by interviewing the administrator or by reviewing hosted applications code, hosted application design documentation, published web services design documentation or ColdFusion baseline documentation.
If web services are not published, this finding is not applicable.
If web services are published, but the SOAP protocol is not used, this finding is not applicable.
If web services are published and the SOAP protocol is used to access data, but the data is not sensitive, this finding is not applicable.
Determine if the ws-security suite is in place to provide secure authentication to the sensitive data by interviewing the administrator or by reviewing hosted applications code, hosted application design documentation, published web services design documentation or ColdFusion baseline documentation.
If web services are published using the SOAP protocol to access sensitive data and the ws-security suite is not used to secure the access, this is a finding.
M
2661