General Application (GAPP) Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000764
- Version
- GAPP-00-000010
- Vuln IDs
-
- V-288135
- Rule IDs
-
- SV-288135r1252910_rule
Checks: C-92819r1252637_chk
Review application documentation and configuration settings to determine if the application is using an approved E-ICAM solution to authenticate organizational users. If an approved E-ICAM solution is not being used, this is a finding. Note: If the site is currently using an enterprise solution (AAA Server) and has documented their plans to move to an approved E-ICAM solution, the severity of this control can be reduced to a CAT III.
Fix: F-92724r1252638_fix
Configure the application to use an approved E-ICAM solution to uniquely identify and authenticate organizational users.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- GAPP-00-000020
- Vuln IDs
-
- V-288136
- Rule IDs
-
- SV-288136r1252911_rule
Checks: C-92820r1252640_chk
Review application documentation and configuration settings to determine if the application is using an approved MFA solution to authenticate organizational users. If an approved MFA solution is not being used, this is a finding.
Fix: F-92725r1252641_fix
Configure the application to use an approved MFA solution to uniquely identify and authenticate organizational users.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- GAPP-00-000030
- Vuln IDs
-
- V-288137
- Rule IDs
-
- SV-288137r1252644_rule
Checks: C-92821r1251994_chk
Navigate to the local account configuration function within the application. Verify no local accounts exist. Otherwise, this is a finding. If a break glass or service account remains, this must be documented and approved by the AO. Otherwise, this is a finding.
Fix: F-92726r1252643_fix
Navigate to the local account configuration function within the application and remove all local accounts. For break glass or service accounts, apply the appropriate password complexity per policy.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- GAPP-00-000040
- Vuln IDs
-
- V-288138
- Rule IDs
-
- SV-288138r1252971_rule
Checks: C-92822r1252645_chk
Navigate to the cryptography configuration for the application's authentication mechanism. SHA 2-384 (or higher) must be used for hashing purposes. If the application's authentication mechanism is not configured to use SHA 2-384 (or higher) for hashing purposes, this is a finding.
Fix: F-92727r1252646_fix
Navigate to the cryptography configuration for the application's authentication mechanism. Configure the authentication mechanism to use SHA 2-384 (or higher) for hashing purposes.
- RMF Control
- Severity
- M
- CCI
- CCI-003627
- Version
- GAPP-00-000050
- Vuln IDs
-
- V-288139
- Rule IDs
-
- SV-288139r1252649_rule
Checks: C-92823r1252000_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable all identifiers after 35 days (or less) of inactivity. Otherwise, this is a finding. If a break glass or service account remains, this must be documented and approved by the authorizing official (AO). Otherwise, this is a finding.
Fix: F-92728r1252648_fix
Navigate to the account configuration function within the application. Configure a policy to disable all identifiers after 35 days (or less) of inactivity. If a break glass or service account remains, this must be documented and approved by the AO. Otherwise, this is a finding.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- GAPP-00-000060
- Vuln IDs
-
- V-288140
- Rule IDs
-
- SV-288140r1252972_rule
Checks: C-92824r1252003_chk
Review the application documentation and deployed configuration to determine whether the application's PKI authentication mechanism validates constructing a certification path (which includes status information) to an accepted trust anchor. If the certification path to an accepted trust anchor cannot be verified for PKI authentication, this is a finding.
Fix: F-92729r1252004_fix
Configure the application's PKI authentication mechanism such that an accepted trust anchor can be verified.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- GAPP-00-000070
- Vuln IDs
-
- V-288141
- Rule IDs
-
- SV-288141r1252008_rule
Checks: C-92825r1252006_chk
Review the application documentation and deployed configuration to determine whether the application's PKI authentication mechanism enforces authorized access to its corresponding private key. If the application's PKI authentication mechanism does not enforce authorized access to its corresponding private key, this is a finding.
Fix: F-92730r1252007_fix
Configure the application's PKI authentication mechanism to enforce authorized access to its corresponding private key.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- GAPP-00-000080
- Vuln IDs
-
- V-288142
- Rule IDs
-
- SV-288142r1252912_rule
Checks: C-92826r1252009_chk
Review the application documentation and deployed configuration to determine whether the application's PKI authentication mechanism maps the authenticated identity to the individual user or group account. If the application's PKI authentication mechanism does not map the authenticated identity to the individual user or group account, this is a finding.
Fix: F-92731r1252010_fix
Configure the application's PKI authentication mechanism to map the authenticated identity to the individual user or group account.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- GAPP-00-000090
- Vuln IDs
-
- V-288143
- Rule IDs
-
- SV-288143r1252014_rule
Checks: C-92827r1252012_chk
Review application server documentation and deployed configuration to ensure the application prohibits the use of cached authenticators after an organization-defined time period. If the application does not prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
Fix: F-92732r1252013_fix
Configure the application to prohibit the use of cached authenticators after an organization-defined time period.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- GAPP-00-000100
- Vuln IDs
-
- V-288144
- Rule IDs
-
- SV-288144r1253072_rule
Checks: C-92828r1253071_chk
Navigate to the CA configuration section of the application. If the application is using CAs that are not DoW approved (or otherwise AO approved), this is a finding.
Fix: F-92733r1252652_fix
Navigate to the CA configuration section of the application. Configure the application to use CAs that are DoW approved (or otherwise AO approved).
- RMF Control
- Severity
- M
- CCI
- CCI-005155
- Version
- GAPP-00-000110
- Vuln IDs
-
- V-288145
- Rule IDs
-
- SV-288145r1252020_rule
Checks: C-92829r1252018_chk
Review the application documentation and deployed configuration to determine whether the application employs identity providers and authorization servers to manage user, device, and NPE identities, attributes, and access rights supporting authentication and authorization decisions in accordance with organization-defined identification and authentication policy using organization-defined mechanisms. If the application does not employ identity providers and authorization servers to manage user, device, and NPE identities, attributes, and access rights supporting authentication and authorization decisions in accordance with organization-defined identification and authentication policy using organization-defined mechanisms, this is a finding.
Fix: F-92734r1252019_fix
Configure the application to employ identity providers and authorization servers to manage user, device, and NPE identities, attributes, and access rights supporting authentication and authorization decisions in accordance with organization-defined identification and authentication policy using organization-defined mechanisms.
- RMF Control
- Severity
- M
- CCI
- CCI-005156
- Version
- GAPP-00-000120
- Vuln IDs
-
- V-288146
- Rule IDs
-
- SV-288146r1252023_rule
Checks: C-92830r1252021_chk
Review the application documentation and deployed configuration to determine whether the application generates, manages, and protects from disclosure and misuse the cryptographic keys that protect access tokens. If the application does not generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens, this is a finding.
Fix: F-92735r1252022_fix
Configure the application to generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.
- RMF Control
- Severity
- M
- CCI
- CCI-005157
- Version
- GAPP-00-000130
- Vuln IDs
-
- V-288147
- Rule IDs
-
- SV-288147r1252026_rule
Checks: C-92831r1252024_chk
Review the application documentation and deployed configuration to determine whether the application protects the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed. If the application does not protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed, this is a finding.
Fix: F-92736r1252025_fix
Configure the application to protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.
- RMF Control
- Severity
- M
- CCI
- CCI-005158
- Version
- GAPP-00-000140
- Vuln IDs
-
- V-288148
- Rule IDs
-
- SV-288148r1252654_rule
Checks: C-92832r1252027_chk
Review the application documentation and deployed configuration to determine whether the application generates assertions in accordance with organization-defined identification and authentication policy. If the application does not generate assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92737r1252028_fix
Configure the application to generate assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005159
- Version
- GAPP-00-000150
- Vuln IDs
-
- V-288149
- Rule IDs
-
- SV-288149r1252655_rule
Checks: C-92833r1252030_chk
Review the application documentation and deployed configuration to determine whether the application issues assertions in accordance with organization-defined identification and authentication policy. If the application does not issue assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92738r1252031_fix
Configure the application to issue assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005160
- Version
- GAPP-00-000160
- Vuln IDs
-
- V-288150
- Rule IDs
-
- SV-288150r1252656_rule
Checks: C-92834r1252033_chk
Review the application documentation and deployed configuration to determine whether the application refreshes assertions in accordance with organization-defined identification and authentication policy. If the application does not refresh assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92739r1252034_fix
Configure the application to refresh assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005161
- Version
- GAPP-00-000170
- Vuln IDs
-
- V-288151
- Rule IDs
-
- SV-288151r1252657_rule
Checks: C-92835r1252036_chk
Review the application documentation and deployed configuration to determine whether the application revokes assertions in accordance with organization-defined identification and authentication policy. If the application does not revoke assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92740r1252037_fix
Configure the application to revoke assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005162
- Version
- GAPP-00-000180
- Vuln IDs
-
- V-288152
- Rule IDs
-
- SV-288152r1252658_rule
Checks: C-92836r1252039_chk
Review the application documentation and deployed configuration to determine whether the application time-restricts assertions in accordance with organization-defined identification and authentication policy. If the application does not time-restrict assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92741r1252040_fix
Configure the application to time-restrict assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005163
- Version
- GAPP-00-000190
- Vuln IDs
-
- V-288153
- Rule IDs
-
- SV-288153r1252659_rule
Checks: C-92837r1252042_chk
Review the application documentation and deployed configuration to determine whether the application audience-restricts assertions in accordance with organization-defined identification and authentication policy. If the application does not audience-restrict assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92742r1252043_fix
Configure the application to audience-restrict assertions in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005164
- Version
- GAPP-00-000200
- Vuln IDs
-
- V-288154
- Rule IDs
-
- SV-288154r1252047_rule
Checks: C-92838r1252045_chk
Review the application documentation and deployed configuration to determine whether the application generates access tokens in accordance with organization-defined identification and authentication policy. If the application does not generate access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92743r1252046_fix
Configure the application to generate access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005165
- Version
- GAPP-00-000210
- Vuln IDs
-
- V-288155
- Rule IDs
-
- SV-288155r1252914_rule
Checks: C-92839r1252048_chk
Review the application documentation and deployed configuration to determine whether the application issues access tokens in accordance with organization-defined identification and authentication policy. If the application does not issue access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92744r1252049_fix
Configure the application to issue access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005166
- Version
- GAPP-00-000220
- Vuln IDs
-
- V-288156
- Rule IDs
-
- SV-288156r1252915_rule
Checks: C-92840r1252051_chk
Review the application documentation and deployed configuration to determine whether the application refreshes access tokens in accordance with organization-defined identification and authentication policy. If the application does not refresh access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92745r1252052_fix
Configure the application to refresh access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005167
- Version
- GAPP-00-000230
- Vuln IDs
-
- V-288157
- Rule IDs
-
- SV-288157r1252916_rule
Checks: C-92841r1252054_chk
Review the application documentation and deployed configuration to determine whether the application revokes access tokens in accordance with organization-defined identification and authentication policy. If the application does not revoke access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92746r1252055_fix
Configure the application to revoke access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005168
- Version
- GAPP-00-000240
- Vuln IDs
-
- V-288158
- Rule IDs
-
- SV-288158r1252917_rule
Checks: C-92842r1252057_chk
Review the application documentation and deployed configuration to determine whether the application time-restricts access tokens in accordance with organization-defined identification and authentication policy. If the application does not time-restrict access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92747r1252058_fix
Configure the application to time-restrict access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- Severity
- M
- CCI
- CCI-005169
- Version
- GAPP-00-000250
- Vuln IDs
-
- V-288159
- Rule IDs
-
- SV-288159r1253074_rule
Checks: C-92843r1253073_chk
Review the application documentation and deployed configuration to determine whether the application audience-restricts access tokens in accordance with organization-defined identification and authentication policy. If the application does not audience-restrict access tokens in accordance with organization-defined identification and authentication policy, this is a finding.
Fix: F-92748r1252061_fix
Configure the application to audience-restrict access tokens in accordance with organization-defined identification and authentication policy.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000016
- Version
- GAPP-00-000260
- Vuln IDs
-
- V-288160
- Rule IDs
-
- SV-288160r1252661_rule
Checks: C-92844r1252660_chk
Navigate to the account configuration function within the application. Verify the application is configured to automatically remove or disable temporary user accounts after 72 hours. Otherwise, this is a finding.
Fix: F-92749r1252064_fix
Navigate to the account configuration function within the application. Configure a policy to automatically remove or disable temporary user accounts after 72 hours.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000017
- Version
- GAPP-00-000270
- Vuln IDs
-
- V-288161
- Rule IDs
-
- SV-288161r1252663_rule
Checks: C-92845r1252662_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable accounts after a 35-day period of account inactivity. Otherwise, this is a finding.
Fix: F-92750r1252067_fix
Navigate to the account configuration function within the application. Configure a policy to disable accounts after a 35-day period of account inactivity.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- GAPP-00-000280
- Vuln IDs
-
- V-288162
- Rule IDs
-
- SV-288162r1252665_rule
Checks: C-92846r1252664_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. Otherwise, this is a finding.
Fix: F-92751r1252070_fix
Navigate to the account configuration function within the application. Configure a policy to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000290
- Vuln IDs
-
- V-288163
- Rule IDs
-
- SV-288163r1252668_rule
Checks: C-92847r1252666_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce a minimum 15-character password length. Otherwise, this is a finding.
Fix: F-92752r1252667_fix
Navigate to the account configuration function within the application. Configure a policy to enforce a minimum 15-character password length.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000300
- Vuln IDs
-
- V-288164
- Rule IDs
-
- SV-288164r1252670_rule
Checks: C-92848r1252669_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce password complexity by requiring that at least one uppercase character be used. Otherwise, this is a finding.
Fix: F-92753r1252076_fix
Navigate to the account configuration function within the application. Configure a policy to enforce password complexity by requiring that at least one uppercase character be used.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000310
- Vuln IDs
-
- V-288165
- Rule IDs
-
- SV-288165r1252672_rule
Checks: C-92849r1252671_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce password complexity by requiring that at least one lowercase character be used. Otherwise, this is a finding.
Fix: F-92754r1252079_fix
Navigate to the account configuration function within the application. Configure a policy to enforce password complexity by requiring that at least one lowercase character be used.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000320
- Vuln IDs
-
- V-288166
- Rule IDs
-
- SV-288166r1252674_rule
Checks: C-92850r1252673_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce password complexity by requiring that at least one numeric character be used. Otherwise, this is a finding.
Fix: F-92755r1252082_fix
Navigate to the account configuration function within the application. Configure a policy to enforce password complexity by requiring that at least one numeric character be used.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000330
- Vuln IDs
-
- V-288167
- Rule IDs
-
- SV-288167r1252676_rule
Checks: C-92851r1252675_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce password complexity by requiring that at least one special character be used. Otherwise, this is a finding.
Fix: F-92756r1252085_fix
Navigate to the account configuration function within the application. Configure a policy to enforce password complexity by requiring that at least one special character be used.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000340
- Vuln IDs
-
- V-288168
- Rule IDs
-
- SV-288168r1252678_rule
Checks: C-92852r1252677_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce password complexity by requiring the change of at least 50 percent of the characters when passwords are changed. Otherwise, this is a finding.
Fix: F-92757r1252088_fix
Navigate to the account configuration function within the application. Configure a policy to enforce password complexity by requiring the change of at least 50 percent of the characters when passwords are changed.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000350
- Vuln IDs
-
- V-288169
- Rule IDs
-
- SV-288169r1252681_rule
Checks: C-92853r1252679_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce 24 hours/one day as the minimum password lifetime. Otherwise, this is a finding.
Fix: F-92758r1252680_fix
Navigate to the account configuration function within the application. Configure a policy to enforce 24 hours/one day as the minimum password lifetime.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000360
- Vuln IDs
-
- V-288170
- Rule IDs
-
- SV-288170r1252683_rule
Checks: C-92854r1252682_chk
Navigate to the account configuration function within the application. Verify the application is configured to enforce a 60-day maximum password lifetime restriction. Otherwise, this is a finding.
Fix: F-92759r1252094_fix
Navigate to the account configuration function within the application. Configure a policy to enforce a 60-day maximum password lifetime restriction.
- RMF Control
- IA-6
- Severity
- M
- CCI
- CCI-000206
- Version
- GAPP-00-000370
- Vuln IDs
-
- V-288171
- Rule IDs
-
- SV-288171r1252098_rule
Checks: C-92855r1252096_chk
Review the application documentation and deployed configuration to determine whether the applications authentication mechanism obscures the feedback of authentication information during the authentication process. If the applications authentication mechanism does not obscure the feedback of authentication information during the authentication process, this is a finding.
Fix: F-92760r1252097_fix
Navigate to the authentication configuration function within the application. Configure the applications authentication mechanism to obscure the feedback of authentication information during the authentication process.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001682
- Version
- GAPP-00-000380
- Vuln IDs
-
- V-288172
- Rule IDs
-
- SV-288172r1252685_rule
Checks: C-92856r1252684_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable temporary and emergency accounts after 72 hours. Otherwise, this is a finding.
Fix: F-92761r1252100_fix
Navigate to the account configuration function within the application. Configure a policy to disable temporary and emergency accounts after 72 hours.
- RMF Control
- Severity
- M
- CCI
- CCI-004045
- Version
- GAPP-00-000390
- Vuln IDs
-
- V-288173
- Rule IDs
-
- SV-288173r1252687_rule
Checks: C-92857r1252686_chk
Navigate to the account/role configuration function within the application. Verify the application is configured to terminate shared/group account credentials when members leave the group. Otherwise, this is a finding.
Fix: F-92762r1252103_fix
Navigate to the account/role configuration function within the application. Configure a policy to terminate shared/group account credentials when members leave the group.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-002238
- Version
- GAPP-00-000400
- Vuln IDs
-
- V-288174
- Rule IDs
-
- SV-288174r1252689_rule
Checks: C-92858r1252688_chk
Navigate to the account configuration function within the application. Verify the application is configured to automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded. Otherwise, this is a finding.
Fix: F-92763r1252106_fix
Navigate to the account configuration function within the application. Configure a policy to automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded.
- RMF Control
- Severity
- M
- CCI
- CCI-003627
- Version
- GAPP-00-000410
- Vuln IDs
-
- V-288175
- Rule IDs
-
- SV-288175r1252691_rule
Checks: C-92859r1252690_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable accounts when the accounts have expired. Otherwise, this is a finding.
Fix: F-92764r1252109_fix
Navigate to the account configuration function within the application. Configure a policy to disable accounts when the accounts have expired.
- RMF Control
- Severity
- M
- CCI
- CCI-003628
- Version
- GAPP-00-000420
- Vuln IDs
-
- V-288176
- Rule IDs
-
- SV-288176r1252693_rule
Checks: C-92860r1252692_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable accounts when the accounts are no longer associated to a user. Otherwise, this is a finding.
Fix: F-92765r1252112_fix
Navigate to the account configuration function within the application. Configure a policy to disable accounts when the accounts are no longer associated to a user.
- RMF Control
- Severity
- M
- CCI
- CCI-003629
- Version
- GAPP-00-000430
- Vuln IDs
-
- V-288177
- Rule IDs
-
- SV-288177r1252695_rule
Checks: C-92861r1252694_chk
Navigate to the account configuration function within the application. Verify the application is configured to disable accounts when the accounts are in violation of organizational policy. Otherwise, this is a finding.
Fix: F-92766r1252115_fix
Navigate to the account configuration function within the application. Configure a policy to disable accounts when the accounts are in violation of organizational policy.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- GAPP-00-000440
- Vuln IDs
-
- V-288178
- Rule IDs
-
- SV-288178r1252698_rule
Checks: C-92862r1252696_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of the password authentication process. If the application's authentication mechanism does not uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of the password authentication process, this is a finding.
Fix: F-92767r1252697_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of the password authentication process.
- RMF Control
- Severity
- M
- CCI
- CCI-004062
- Version
- GAPP-00-000450
- Vuln IDs
-
- V-288179
- Rule IDs
-
- SV-288179r1252701_rule
Checks: C-92863r1252699_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism stores only cryptographic representations of passwords. If the application's authentication mechanism does not store only cryptographic representations of passwords, this is a finding.
Fix: F-92768r1252700_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to store only cryptographic representations of passwords.
- RMF Control
- Severity
- M
- CCI
- CCI-004058
- Version
- GAPP-00-000460
- Vuln IDs
-
- V-288180
- Rule IDs
-
- SV-288180r1252704_rule
Checks: C-92864r1252702_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism maintains a list of commonly used, expected, or compromised passwords on an organization-defined frequency. If the application's authentication mechanism does not maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency, this is a finding.
Fix: F-92769r1252703_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- RMF Control
- Severity
- M
- CCI
- CCI-004059
- Version
- GAPP-00-000470
- Vuln IDs
-
- V-288181
- Rule IDs
-
- SV-288181r1252707_rule
Checks: C-92865r1252705_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism updates the list of known passwords on an organization-defined frequency. If the application's authentication mechanism does not maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency, this is a finding.
Fix: F-92770r1252706_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to update the list of known passwords on an organization-defined frequency.
- RMF Control
- Severity
- M
- CCI
- CCI-004060
- Version
- GAPP-00-000480
- Vuln IDs
-
- V-288182
- Rule IDs
-
- SV-288182r1252710_rule
Checks: C-92866r1252708_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly. If the application's authentication mechanism does not update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly, this is a finding.
Fix: F-92771r1252709_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
- RMF Control
- Severity
- M
- CCI
- CCI-004061
- Version
- GAPP-00-000490
- Vuln IDs
-
- V-288183
- Rule IDs
-
- SV-288183r1252920_rule
Checks: C-92867r1252919_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism verifies when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a). If the application's authentication mechanism does not verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a), this is a finding.
Fix: F-92772r1252712_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- RMF Control
- Severity
- M
- CCI
- CCI-004062
- Version
- GAPP-00-000500
- Vuln IDs
-
- V-288184
- Rule IDs
-
- SV-288184r1252716_rule
Checks: C-92868r1252714_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism stores passwords using an approved salted key derivation function, preferably using a keyed hash. If the application's authentication mechanism does not store passwords using an approved salted key derivation function, preferably using a keyed hash, this is a finding.
Fix: F-92773r1252715_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to store passwords using an approved salted key derivation function, preferably using a keyed hash.
- RMF Control
- Severity
- M
- CCI
- CCI-004063
- Version
- GAPP-00-000510
- Vuln IDs
-
- V-288185
- Rule IDs
-
- SV-288185r1252719_rule
Checks: C-92869r1252717_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism requires immediate selection of a new password upon account recovery. If the application's authentication mechanism does not require immediate selection of a new password upon account recovery, this is a finding.
Fix: F-92774r1252718_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to require immediate selection of a new password upon account recovery.
- RMF Control
- Severity
- M
- CCI
- CCI-004064
- Version
- GAPP-00-000520
- Vuln IDs
-
- V-288186
- Rule IDs
-
- SV-288186r1252722_rule
Checks: C-92870r1252720_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism allows user selection of long passwords and passphrases, including spaces and all printable characters. If the application's authentication mechanism does not allow user selection of long passwords and passphrases, including spaces and all printable characters, this is a finding.
Fix: F-92775r1252721_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to require user selection of long passwords and passphrases, including spaces and all printable characters, this is a finding.
- RMF Control
- Severity
- M
- CCI
- CCI-004065
- Version
- GAPP-00-000530
- Vuln IDs
-
- V-288187
- Rule IDs
-
- SV-288187r1252725_rule
Checks: C-92871r1252723_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism employs automated tools to assist the user in selecting strong password authenticators. If the application's authentication mechanism does not employ automated tools to assist the user in selecting strong password authenticators, this is a finding.
Fix: F-92776r1252724_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to employ automated tools to assist the user in selecting strong password authenticators, this is a finding.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- GAPP-00-000540
- Vuln IDs
-
- V-288188
- Rule IDs
-
- SV-288188r1252728_rule
Checks: C-92872r1252726_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism enforces organization-defined composition and complexity rules. If the application's authentication mechanism does not enforce organization-defined composition and complexity rules, this is a finding.
Fix: F-92777r1252727_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to enforce organization-defined composition and complexity rules.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- GAPP-00-000550
- Vuln IDs
-
- V-288189
- Rule IDs
-
- SV-288189r1252731_rule
Checks: C-92873r1252729_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism limits the number of concurrent sessions to a maximum number of three for all accounts and/or account types. If the application's authentication mechanism does not limit the number of concurrent sessions to a maximum number of three for all accounts and/or account types, this is a finding.
Fix: F-92778r1252730_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to limit the number of concurrent sessions to a maximum number of three for all accounts and/or account types.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- GAPP-00-000560
- Vuln IDs
-
- V-288190
- Rule IDs
-
- SV-288190r1252155_rule
Checks: C-92874r1252153_chk
Review the application documentation and deployed configuration to determine whether the application terminates all network connections associated with a communications session at the end of the session, or no more than 15 minutes of inactivity. If the application does not terminate all network connections associated with a communications session at the end of the session, or no more than 15 minutes of inactivity, this is a finding.
Fix: F-92779r1252154_fix
Configure the application to terminate all network connections associated with a communications session at the end of the session, or no more than 15 minutes of inactivity.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001185
- Version
- GAPP-00-000570
- Vuln IDs
-
- V-288191
- Rule IDs
-
- SV-288191r1252921_rule
Checks: C-92875r1252156_chk
Review the application documentation and deployed configuration to determine whether the application invalidates session identifiers upon user logout or other session termination. If the application does not invalidate session identifiers upon user logout or other session termination, this is a finding.
Fix: F-92780r1252157_fix
Configure the application to invalidate session identifiers upon user logout or other session termination.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001664
- Version
- GAPP-00-000580
- Vuln IDs
-
- V-288192
- Rule IDs
-
- SV-288192r1252161_rule
Checks: C-92876r1252159_chk
Review the application documentation and deployed configuration to determine whether the application recognizes only system-generated session IDs. If the application does not recognize only system-generated session IDs, this is a finding.
Fix: F-92781r1252160_fix
Configure the application to recognize only system-generated session IDs.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001188
- Version
- GAPP-00-000590
- Vuln IDs
-
- V-288193
- Rule IDs
-
- SV-288193r1253076_rule
Checks: C-92877r1252922_chk
Review the application documentation and deployed configuration to determine whether the application generates unique session identifiers using a FIPS-validated RNG based on the DRBG algorithm. If the application does not generate unique session identifiers using a FIPS-validated RNG based on the DRBG algorithm, this is a finding.
Fix: F-92782r1253075_fix
Configure the application to generate unique session identifiers using a FIPS-validated RNG based on the DRBG algorithm.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002363
- Version
- GAPP-00-000600
- Vuln IDs
-
- V-288194
- Rule IDs
-
- SV-288194r1252926_rule
Checks: C-92878r1252924_chk
Review the application documentation and deployed configuration to determine whether the application provides a logout function for user-initiated communication sessions. If the application does not provide a logout function for user-initiated communication sessions, this is a finding.
Fix: F-92783r1252925_fix
Configure the application to provide a logout function for user-initiated communication sessions.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002364
- Version
- GAPP-00-000610
- Vuln IDs
-
- V-288195
- Rule IDs
-
- SV-288195r1252170_rule
Checks: C-92879r1252168_chk
Review the application documentation and deployed configuration to determine whether the application displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions. If the application does not display an explicit logout message to users indicating the reliable termination of authenticated communications sessions, this is a finding.
Fix: F-92784r1252169_fix
Configure the application to display an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- GAPP-00-000620
- Vuln IDs
-
- V-288196
- Rule IDs
-
- SV-288196r1252173_rule
Checks: C-92880r1252171_chk
Review the application documentation and deployed configuration to determine whether the application requires users to reauthenticate when organization-defined circumstances or situations require reauthentication. If the application does not require users to reauthenticate when organization-defined circumstances or situations require reauthentication, this is a finding.
Fix: F-92785r1252172_fix
Configure the application to require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- GAPP-00-000630
- Vuln IDs
-
- V-288197
- Rule IDs
-
- SV-288197r1252733_rule
Checks: C-92881r1252732_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism audits account creation. If the application's authentication mechanism does not audit account creation, this is a finding.
Fix: F-92786r1252515_fix
Configure the application to automatically audit account creation.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000640
- Vuln IDs
-
- V-288198
- Rule IDs
-
- SV-288198r1252973_rule
Checks: C-92882r1252927_chk
Review the application documentation and deployed configuration to determine whether the application's authentication mechanism audits account modifications to include disabling/removal actions, and attempts to access privileges. If the application's authentication mechanism does not audit account modifications to include disabling/removal actions and attempts to access privileges, this is a finding.
Fix: F-92787r1252735_fix
Navigate to the authentication configuration function within the application. Configure the application's authentication mechanism to audit account modifications to include disabling/removal actions, and attempts to access privileges.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001314
- Version
- GAPP-00-000650
- Vuln IDs
-
- V-288199
- Rule IDs
-
- SV-288199r1252738_rule
Checks: C-92883r1252477_chk
Review the application documentation and deployed configuration to determine whether the application reveals error messages only to the ISSO/ISSM, if assigned, and/or security personnel as appropriate. If the application does not reveal error messages only to the ISSO/ISSM, if assigned, and/or security personnel as appropriate, this is a finding.
Fix: F-92788r1252737_fix
Navigate to the authentication configuration function within the application. Configure the application to only reveal error messages to the ISSO, information ISSM, if assigned, and/or security personnel as appropriate.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- GAPP-00-000660
- Vuln IDs
-
- V-288200
- Rule IDs
-
- SV-288200r1252741_rule
Checks: C-92884r1252739_chk
Review the application documentation and deployed configuration to determine whether the application's alerting mechanism alerts the ISSO/ISSM at a minimum (if assigned) and/or security personnel as appropriate. If the application's alerting mechanism does not audit alerts the ISSO/ISSM at a minimum (if assigned) and/or security personnel as appropriate, this is a finding.
Fix: F-92789r1252740_fix
Navigate to the alerting function configuration within the application. Configure the application to alert the ISSO and ISSM, at a minimum, in the event of audit processing failure.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- GAPP-00-000670
- Vuln IDs
-
- V-288201
- Rule IDs
-
- SV-288201r1252929_rule
Checks: C-92885r1252186_chk
Review the application documentation and deployed configuration to determine if error messages generated by the application only provide the information necessary for corrective actions without revealing information that could be exploited. If error messages contain information that could be exploited, this is a finding.
Fix: F-92790r1252187_fix
Configure that application to only provide the information necessary for corrective actions without revealing information that could be exploited.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- GAPP-00-000680
- Vuln IDs
-
- V-288202
- Rule IDs
-
- SV-288202r1252930_rule
Checks: C-92886r1252742_chk
Review the application documentation and deployed configuration to determine whether the application's alerting mechanism notifies SAs and the ISSO when accounts are created. If the application's alerting mechanism does not notify SAs and the ISSO when accounts are created, this is a finding.
Fix: F-92791r1252743_fix
Navigate to the alerting function configuration within the application. Configure the application's alerting mechanism to notify SAs and the ISSO when accounts are created.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- GAPP-00-000690
- Vuln IDs
-
- V-288203
- Rule IDs
-
- SV-288203r1252747_rule
Checks: C-92887r1252745_chk
Review the application documentation and deployed configuration to determine whether the application's alerting mechanism notifies SAs and the ISSO when accounts are modified to include disabling and removal actions. If the application's alerting mechanism does not notify SAs and the ISSO when accounts are modified to include disabling and removal actions, this is a finding.
Fix: F-92792r1252746_fix
Navigate to the alerting function configuration within the application. Configure the application's alerting mechanism to notify SAs and the ISSO when accounts are modified to include disabling and removal actions.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000171
- Version
- GAPP-00-000700
- Vuln IDs
-
- V-288204
- Rule IDs
-
- SV-288204r1252932_rule
Checks: C-92888r1252748_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism allows only the ISSM, or individuals or roles appointed by the ISSM, to select which auditable events are to be audited. If the application's auditing mechanism does not allow only the ISSM, or individuals or roles appointed by the ISSM, to select which auditable events are to be audited, this is a finding.
Fix: F-92793r1252931_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to allow only the ISSM, or individuals or roles appointed by the ISSM, to select which auditable events are to be audited.
- RMF Control
- AU-14
- Severity
- M
- CCI
- CCI-001464
- Version
- GAPP-00-000710
- Vuln IDs
-
- V-288205
- Rule IDs
-
- SV-288205r1252753_rule
Checks: C-92889r1252751_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism initiates session auditing upon startup. If the application's auditing mechanism does not initiate session auditing upon startup, this is a finding.
Fix: F-92794r1252752_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to initiate session auditing upon startup.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- GAPP-00-000720
- Vuln IDs
-
- V-288206
- Rule IDs
-
- SV-288206r1252756_rule
Checks: C-92890r1252754_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing descriptions of the audit events. If the application's auditing mechanism does not produce audit records containing descriptions of the audit events, this is a finding.
Fix: F-92795r1252755_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records containing descriptions of the audit events.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- GAPP-00-000730
- Vuln IDs
-
- V-288207
- Rule IDs
-
- SV-288207r1252759_rule
Checks: C-92891r1252757_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing information to establish when (date and time) the events occurred. If the application's auditing mechanism does not produce audit records containing information to establish when (date and time) the events occurred, this is a finding.
Fix: F-92796r1252758_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records containing information to establish when (date and time) the events occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- GAPP-00-000740
- Vuln IDs
-
- V-288208
- Rule IDs
-
- SV-288208r1252762_rule
Checks: C-92892r1252760_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing information to establish source and destination addresses. If the application's auditing mechanism does not produce audit records containing information to establish source and destination addresses, this is a finding.
Fix: F-92797r1252761_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records containing information to establish source and destination addresses.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- GAPP-00-000750
- Vuln IDs
-
- V-288209
- Rule IDs
-
- SV-288209r1252765_rule
Checks: C-92893r1252763_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records that contain information to establish success indicators, fail indicators, and enforcement actions. If the application's auditing mechanism does not produce audit records that contain information to establish success indicators, fail indicators, and enforcement actions, this is a finding.
Fix: F-92798r1252764_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records that contain information to establish success indicators, fail indicators, and enforcement actions.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- GAPP-00-000760
- Vuln IDs
-
- V-288210
- Rule IDs
-
- SV-288210r1252768_rule
Checks: C-92894r1252766_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records containing information that establishes the identity of any individual or process associated with the event. If the application's auditing mechanism does not generate audit records containing information that establishes the identity of any individual or process associated with the event, this is a finding.
Fix: F-92799r1252767_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records containing information that establishes the identity of any individual or process associated with the event.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- GAPP-00-000770
- Vuln IDs
-
- V-288211
- Rule IDs
-
- SV-288211r1252771_rule
Checks: C-92895r1252769_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism protects audit information from any type of unauthorized read access. If the application's auditing mechanism does not protect audit information from any type of unauthorized read access, this is a finding.
Fix: F-92800r1252770_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to protect audit information from any type of unauthorized read access.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- GAPP-00-000780
- Vuln IDs
-
- V-288212
- Rule IDs
-
- SV-288212r1252974_rule
Checks: C-92896r1252772_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism protects audit information from unauthorized modification. If the application's auditing mechanism does not protect audit information from unauthorized modification, this is a finding.
Fix: F-92801r1252773_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to protect audit information from unauthorized modification.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- GAPP-00-000790
- Vuln IDs
-
- V-288213
- Rule IDs
-
- SV-288213r1252933_rule
Checks: C-92897r1252775_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism protects audit information from unauthorized deletion. If the application's auditing mechanism does not protect audit information from unauthorized deletion, this is a finding.
Fix: F-92802r1252776_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to protect audit information from unauthorized deletion.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001493
- Version
- GAPP-00-000800
- Vuln IDs
-
- V-288214
- Rule IDs
-
- SV-288214r1252934_rule
Checks: C-92898r1252778_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism protects audit tools from unauthorized access. If the application's auditing mechanism does not protect audit tools from unauthorized access, this is a finding.
Fix: F-92803r1252779_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to protect audit tools from unauthorized access.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-002130
- Version
- GAPP-00-000810
- Vuln IDs
-
- V-288215
- Rule IDs
-
- SV-288215r1252783_rule
Checks: C-92899r1252781_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism audits account enabling actions. If the application's auditing mechanism does not audit account enabling actions, this is a finding.
Fix: F-92804r1252782_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to audit account enabling actions.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001889
- Version
- GAPP-00-000820
- Vuln IDs
-
- V-288216
- Rule IDs
-
- SV-288216r1252786_rule
Checks: C-92900r1252784_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism records time stamps for audit records that meet a granularity of one second for a minimum degree of precision. If the application's auditing mechanism does not record time stamps for audit records that meet a granularity of one second for a minimum degree of precision, this is a finding.
Fix: F-92805r1252785_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000830
- Vuln IDs
-
- V-288217
- Rule IDs
-
- SV-288217r1252789_rule
Checks: C-92901r1252787_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to access security objects occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to access security objects occur, this is a finding.
Fix: F-92806r1252788_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to access security objects occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000840
- Vuln IDs
-
- V-288218
- Rule IDs
-
- SV-288218r1252792_rule
Checks: C-92902r1252790_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to access security levels occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to access security levels occur, this is a finding.
Fix: F-92807r1252791_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to access security levels occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000850
- Vuln IDs
-
- V-288219
- Rule IDs
-
- SV-288219r1252795_rule
Checks: C-92903r1252793_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur, this is a finding.
Fix: F-92808r1252794_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000860
- Vuln IDs
-
- V-288220
- Rule IDs
-
- SV-288220r1252798_rule
Checks: C-92904r1252796_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to modify privileges occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to modify privileges occur, this is a finding.
Fix: F-92809r1252797_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to modify privileges occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000870
- Vuln IDs
-
- V-288221
- Rule IDs
-
- SV-288221r1252801_rule
Checks: C-92905r1252799_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to modify security objects occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to modify security objects occur, this is a finding.
Fix: F-92810r1252800_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to modify security objects occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000880
- Vuln IDs
-
- V-288222
- Rule IDs
-
- SV-288222r1252804_rule
Checks: C-92906r1252802_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to modify security levels occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to modify security levels occur, this is a finding.
Fix: F-92811r1252803_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to modify security levels occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000890
- Vuln IDs
-
- V-288223
- Rule IDs
-
- SV-288223r1252807_rule
Checks: C-92907r1252805_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur, this is a finding.
Fix: F-92812r1252806_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000900
- Vuln IDs
-
- V-288224
- Rule IDs
-
- SV-288224r1252810_rule
Checks: C-92908r1252808_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to delete privileges occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to delete privileges occur, this is a finding.
Fix: F-92813r1252809_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to delete privileges occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000910
- Vuln IDs
-
- V-288225
- Rule IDs
-
- SV-288225r1252813_rule
Checks: C-92909r1252811_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to delete security levels occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to delete security levels occur, this is a finding.
Fix: F-92814r1252812_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to delete security levels occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000920
- Vuln IDs
-
- V-288226
- Rule IDs
-
- SV-288226r1252816_rule
Checks: C-92910r1252814_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to delete security objects occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to delete security objects occur, this is a finding.
Fix: F-92815r1252815_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to delete security objects occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000930
- Vuln IDs
-
- V-288227
- Rule IDs
-
- SV-288227r1252819_rule
Checks: C-92911r1252817_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur, this is a finding.
Fix: F-92816r1252818_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000940
- Vuln IDs
-
- V-288228
- Rule IDs
-
- SV-288228r1252822_rule
Checks: C-92912r1252820_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful logon attempts occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful logon attempts occur, this is a finding.
Fix: F-92817r1252821_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful logon attempts occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000950
- Vuln IDs
-
- V-288229
- Rule IDs
-
- SV-288229r1252825_rule
Checks: C-92913r1252823_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records for privileged activities or other system-level access. If the application's auditing mechanism does not generate audit records for privileged activities or other system-level access, this is a finding.
Fix: F-92818r1252824_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records for privileged activities or other system-level access.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000960
- Vuln IDs
-
- V-288230
- Rule IDs
-
- SV-288230r1252936_rule
Checks: C-92914r1252826_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records showing starting and ending time for user access to the system. If the application's auditing mechanism does not generate audit records showing starting and ending time for user access to the system, this is a finding.
Fix: F-92819r1252935_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records showing start and end times for user access to the system.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000970
- Vuln IDs
-
- V-288231
- Rule IDs
-
- SV-288231r1252831_rule
Checks: C-92915r1252829_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when concurrent logons from different workstations occur. If the application's auditing mechanism does not generate audit records when concurrent logons from different workstations occur, this is a finding.
Fix: F-92820r1252830_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when concurrent logons from different workstations occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000980
- Vuln IDs
-
- V-288232
- Rule IDs
-
- SV-288232r1252834_rule
Checks: C-92916r1252832_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records when successful/unsuccessful accesses to objects occur. If the application's auditing mechanism does not generate audit records when successful/unsuccessful accesses to objects occur, this is a finding.
Fix: F-92821r1252833_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records when successful/unsuccessful accesses to objects occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-000990
- Vuln IDs
-
- V-288233
- Rule IDs
-
- SV-288233r1252837_rule
Checks: C-92917r1252835_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records for all direct access to the information system. If the application's auditing mechanism does not generate audit records for all direct access to the information system, this is a finding.
Fix: F-92822r1252836_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records for all direct access to the information system.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-001000
- Vuln IDs
-
- V-288234
- Rule IDs
-
- SV-288234r1252840_rule
Checks: C-92918r1252838_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records for all account creations, modifications, disabling, and termination events. If the application's auditing mechanism does not generate audit records for all account creations, modifications, disabling, and termination events, this is a finding.
Fix: F-92823r1252839_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records for all account creations, modifications, disabling, and termination events.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- GAPP-00-001010
- Vuln IDs
-
- V-288235
- Rule IDs
-
- SV-288235r1252843_rule
Checks: C-92919r1252841_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism generates audit records for all module load, unload, and restart events and, also for all program initiations. If the application's auditing mechanism does not generate audit records for all module load, unload, and restart events and, also for all program initiations, this is a finding.
Fix: F-92824r1252842_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate audit records for all module load, unload, and restart events and, also for all program initiations.
- RMF Control
- CM-3
- Severity
- M
- CCI
- CCI-001744
- Version
- GAPP-00-001020
- Vuln IDs
-
- V-288236
- Rule IDs
-
- SV-288236r1252938_rule
Checks: C-92920r1252844_chk
Review the application documentation and deployed configuration to determine whether the application's alerting mechanism notifies the ISSO/ISSM, and rolls back the unauthorized change, when baseline configurations are changed in an unauthorized manner. If the application's alerting mechanism does not notify the ISSO/ISSM, and rolls back the unauthorized change, when baseline configurations are changed in an unauthorized manner, this is a finding.
Fix: F-92825r1252937_fix
Navigate to the alerting function configuration within the application. Configure the application's alerting mechanism to notify the ISSO/ISSM and undo the unauthorized change when baseline configurations are changed in an unauthorized manner.
- RMF Control
- MA-3
- Severity
- M
- CCI
- CCI-002883
- Version
- GAPP-00-001030
- Vuln IDs
-
- V-288237
- Rule IDs
-
- SV-288237r1252487_rule
Checks: C-92921r1252486_chk
If the application is not a maintenance application, this requirement is Not Applicable. Review the maintenance application documentation and deployed configuration to determine whether performance of maintenance functions is restricted to authorized personnel only. If the maintenance application does not restrict maintenance functions to authorized personnel only, this is a finding.
Fix: F-92826r1252295_fix
Configure the maintenance application to restrict the performance of maintenance functions to authorized personnel only.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002884
- Version
- GAPP-00-001040
- Vuln IDs
-
- V-288238
- Rule IDs
-
- SV-288238r1252299_rule
Checks: C-92922r1252297_chk
If the application is not a maintenance application, this requirement is Not Applicable. Review the application's documentation and deployed configuration to determine whether the auditing mechanism generates organization-defined audit records for nonlocal maintenance and diagnostic sessions. If the application's auditing mechanism does not generate audit records for nonlocal maintenance and diagnostic session organization-defined audit events, this is a finding.
Fix: F-92827r1252298_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate organization-defined audit records for nonlocal maintenance and diagnostic sessions.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-001632
- Version
- GAPP-00-001050
- Vuln IDs
-
- V-288239
- Rule IDs
-
- SV-288239r1252941_rule
Checks: C-92923r1252939_chk
If the application is not a maintenance application, this requirement is Not Applicable. Review the maintenance application documentation and deployed configuration to determine whether the nonlocal maintenance sessions are protected by separating the maintenance session from other network sessions by either physically separated communications paths or logically separated communications paths based upon encryption. If the maintenance application does not protect nonlocal maintenance sessions by separating the maintenance session from other network sessions by either physically separated communications paths or logically separated communications paths based upon encryption, this is a finding.
Fix: F-92828r1252940_fix
Configure the maintenance application to protect nonlocal maintenance sessions by separating the maintenance session from other network sessions by either physically separated communications paths or logically separated communications paths based upon encryption.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- GAPP-00-001060
- Vuln IDs
-
- V-288240
- Rule IDs
-
- SV-288240r1252944_rule
Checks: C-92924r1252942_chk
If the application is not a maintenance application, this requirement is Not Applicable. If the maintenance application does not use FIPS-validated keyed HMAC to protect the integrity of nonlocal maintenance and diagnostic communications, this is a finding.
Fix: F-92829r1252943_fix
Configure the maintenance application to use FIPS-validated keyed HMAC to protect the integrity of nonlocal maintenance and diagnostic communications.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002891
- Version
- GAPP-00-001070
- Vuln IDs
-
- V-288241
- Rule IDs
-
- SV-288241r1252308_rule
Checks: C-92925r1252306_chk
If the application is not a maintenance application, this requirement is Not Applicable. Review the maintenance application documentation and deployed configuration to determine whether remote session disconnection occurs at the termination of nonlocal maintenance and diagnostic sessions. If the maintenance application does not, upon the termination of nonlocal maintenance and diagnostic sessions, remotely disconnect the session, this is a finding.
Fix: F-92830r1252307_fix
Configure the maintenance application to remotely disconnect the session upon the termination of nonlocal maintenance and diagnostic sessions.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- GAPP-00-001080
- Vuln IDs
-
- V-288242
- Rule IDs
-
- SV-288242r1252848_rule
Checks: C-92926r1252847_chk
Navigate to the logon banner configuration function within the application. Verify the application retains the Standard Mandatory DoW Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access. Otherwise, this is a finding.
Fix: F-92831r1252310_fix
Navigate to the logon banner configuration function within the application. Configure the application to retain the Standard Mandatory DoW Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- GAPP-00-001090
- Vuln IDs
-
- V-288243
- Rule IDs
-
- SV-288243r1252491_rule
Checks: C-92927r1252490_chk
Navigate to the logon banner configuration function within the publicly accessible application. Verify the publicly accessible application retains the Standard Mandatory DoW Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access. Otherwise, this is a finding.
Fix: F-92832r1252313_fix
Navigate to the logon banner configuration function within the publicly accessible application. Configure the publicly accessible application to retain the Standard Mandatory DoW Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AU-9
- Severity
- H
- CCI
- CCI-001348
- Version
- GAPP-00-001100
- Vuln IDs
-
- V-288244
- Rule IDs
-
- SV-288244r1252851_rule
Checks: C-92928r1252849_chk
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism off-loads audit records onto a central logging system at least every seven days. If the application's auditing mechanism does not off-load audit records onto a central logging system at least every seven days, this is a finding.
Fix: F-92833r1252850_fix
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to off-load audit records onto a central logging system at least every seven days.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- GAPP-00-001110
- Vuln IDs
-
- V-288245
- Rule IDs
-
- SV-288245r1252945_rule
Checks: C-92929r1252852_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes, this is a finding.
Fix: F-92834r1252853_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- GAPP-00-001120
- Vuln IDs
-
- V-288246
- Rule IDs
-
- SV-288246r1252946_rule
Checks: C-92930r1252855_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses CNSA 2.0 cryptographic algorithms. If the application's cryptography mechanism does not use CNSA 2.0 cryptographic algorithms, this is a finding.
Fix: F-92835r1252856_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use CNSA 2.0 cryptographic algorithms.
- RMF Control
- IA-7
- Severity
- H
- CCI
- CCI-000803
- Version
- GAPP-00-001130
- Vuln IDs
-
- V-288247
- Rule IDs
-
- SV-288247r1252860_rule
Checks: C-92931r1252858_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated SHA-2 or higher hash function for digital signature generation and verification. If the application's cryptography mechanism does not use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification, this is a finding.
Fix: F-92836r1252859_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- GAPP-00-001140
- Vuln IDs
-
- V-288248
- Rule IDs
-
- SV-288248r1252947_rule
Checks: C-92932r1252861_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses a FIPS-validated cryptographic module to provision digital signatures. If the application's cryptography mechanism does not use a FIPS-validated cryptographic module to provision digital signatures, this is a finding.
Fix: F-92837r1252862_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use a FIPS-validated cryptographic module to provision digital signatures.
- RMF Control
- SC-28
- Severity
- H
- CCI
- CCI-002475
- Version
- GAPP-00-001150
- Vuln IDs
-
- V-288249
- Rule IDs
-
- SV-288249r1252866_rule
Checks: C-92933r1252864_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism prevents unauthorized modification of information at rest. If the application's cryptography mechanism does not prevent unauthorized modification of information at rest, this is a finding.
Fix: F-92838r1252865_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to prevent unauthorized modification of information at rest.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- GAPP-00-001160
- Vuln IDs
-
- V-288250
- Rule IDs
-
- SV-288250r1252948_rule
Checks: C-92934r1252867_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions, this is a finding.
Fix: F-92839r1252868_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- GAPP-00-001170
- Vuln IDs
-
- V-288251
- Rule IDs
-
- SV-288251r1252949_rule
Checks: C-92935r1252870_chk
Review the application documentation and deployed configuration to determine whether the application's remote access mechanism monitors remote access methods. If the application's remote access mechanism does not monitor remote access methods, this is a finding.
Fix: F-92840r1252871_fix
Navigate to the remote access configuration within the application. Configure the application's remote access mechanism to monitor remote access methods.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- GAPP-00-001180
- Vuln IDs
-
- V-288252
- Rule IDs
-
- SV-288252r1252950_rule
Checks: C-92936r1252873_chk
Review the application documentation and deployed configuration to determine whether the application's remote access mechanism controls remote access methods. If the application's remote access mechanism does not control remote access methods, this is a finding.
Fix: F-92841r1252874_fix
Navigate to the remote access configuration within the application. Configure the application's remote access mechanism to control remote access methods.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- GAPP-00-001190
- Vuln IDs
-
- V-288253
- Rule IDs
-
- SV-288253r1252951_rule
Checks: C-92937r1252876_chk
Review the application documentation and deployed configuration to determine whether the application's remote access mechanism uses TLS 1.2 or greater to protect the confidentiality and integrity of all remote access sessions. If the application's remote access mechanism does not use TLS 1.2 or greater to protect the confidentiality and integrity of all remote access sessions, this is a finding.
Fix: F-92842r1252877_fix
Navigate to the remote access configuration within the application. Configure the application's remote access mechanism to use TLS 1.2 or greater to protect the confidentiality and integrity of all remote access sessions.
- RMF Control
- SC-23
- Severity
- H
- CCI
- CCI-001184
- Version
- GAPP-00-001200
- Vuln IDs
-
- V-288254
- Rule IDs
-
- SV-288254r1252952_rule
Checks: C-92938r1252879_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the confidentiality and integrity of transmitted information. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the confidentiality and integrity of transmitted information, this is a finding.
Fix: F-92843r1252880_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the confidentiality and integrity of transmitted information.
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-003123
- Version
- GAPP-00-001210
- Vuln IDs
-
- V-288255
- Rule IDs
-
- SV-288255r1253077_rule
Checks: C-92939r1252882_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications, this is a finding.
Fix: F-92844r1252883_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-001453
- Version
- GAPP-00-001220
- Vuln IDs
-
- V-288256
- Rule IDs
-
- SV-288256r1252887_rule
Checks: C-92940r1252885_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism prohibits client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0. If the application's cryptography mechanism does not prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0, this is a finding.
Fix: F-92845r1252886_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- GAPP-00-001230
- Vuln IDs
-
- V-288257
- Rule IDs
-
- SV-288257r1252890_rule
Checks: C-92941r1252888_chk
Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B for authentication to a cryptographic module. If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B for authentication to a cryptographic module, this is a finding.
Fix: F-92846r1252889_fix
Navigate to the cryptography configuration within the application. Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B for authentication to a cryptographic module.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- GAPP-00-001240
- Vuln IDs
-
- V-288258
- Rule IDs
-
- SV-288258r1252892_rule
Checks: C-92942r1252891_chk
Review the application documentation and deployed configuration to determine whether the application validates certificates used for TLS functions by performing RFC 5280-compliant certification path validation. OSCP is used to accomplish this. If the application does not validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation, this is a finding.
Fix: F-92847r1252358_fix
Configure the application to validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
- RMF Control
- Severity
- M
- CCI
- CCI-004068
- Version
- GAPP-00-001250
- Vuln IDs
-
- V-288259
- Rule IDs
-
- SV-288259r1252954_rule
Checks: C-92943r1252360_chk
CRL must only be used as a fallback if an OSCP function is not available. Review the application documentation and deployed configuration to determine whether the application, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. If the application does not, for PKI-based authentication, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, this is a finding.
Fix: F-92848r1252953_fix
For PKI-based authentication without OSCP, configure the application to implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
- RMF Control
- Severity
- M
- CCI
- CCI-004068
- Version
- GAPP-00-001260
- Vuln IDs
-
- V-288260
- Rule IDs
-
- SV-288260r1252975_rule
Checks: C-92944r1252363_chk
CRL must only be used as a fallback if an OSCP function is not available. Review the application documentation and deployed configuration to determine whether the application, for public key-based authentication, implements a local cache of revocation data to support path discovery and validation. If the application does not, for public key-based authentication, implement a local cache of revocation data to support path discovery and validation, this is a finding.
Fix: F-92849r1252955_fix
For public key-based authentication without OSCP, configure the application to implement a local cache of revocation data to support path discovery and validation.
- RMF Control
- Severity
- M
- CCI
- CCI-004909
- Version
- GAPP-00-001270
- Vuln IDs
-
- V-288261
- Rule IDs
-
- SV-288261r1252368_rule
Checks: C-92945r1252366_chk
CRL must only be used as a fallback if an OSCP function is not available. Review the application documentation and deployed configuration to determine whether the application includes only approved trust anchors in trust stores or certificate stores managed by the organization. If the application does not include only approved trust anchors in trust stores or certificate stores managed by the organization, this is a finding.
Fix: F-92850r1252367_fix
Configure the application to include only approved trust anchors in trust stores or certificate stores managed by the organization.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- GAPP-00-001280
- Vuln IDs
-
- V-288262
- Rule IDs
-
- SV-288262r1252957_rule
Checks: C-92946r1252369_chk
Navigate to the user/role configuration function within the application. The role-based hierarchical structure must be defined by the authorizing official (AO) (or otherwise appointed personnel). 1. Verify at least two roles exist in the structure. 2.Verify at least one user is assigned to each role. Otherwise, this is a finding.
Fix: F-92851r1252370_fix
Navigate to the user/role configuration function within the application. The role-based hierarchical structure must be defined by the AO (or otherwise appointed personnel). 1. Create at least two roles in the structure. 2. Assign at least one user to each role.
- RMF Control
- SC-2
- Severity
- M
- CCI
- CCI-001082
- Version
- GAPP-00-001290
- Vuln IDs
-
- V-288263
- Rule IDs
-
- SV-288263r1252958_rule
Checks: C-92947r1252893_chk
Review the application documentation and deployed configuration to determine whether user functionality (including user interface services) is separated from information system management functionality. If the application's user functionality (including user interface services) is not separated from information system management functionality, this is a finding.
Fix: F-92852r1252373_fix
Navigate to the cryptography configuration within the application. Configure the application to separate user functionality (including user interface services) from information system management functionality.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-001424
- Version
- GAPP-00-001300
- Vuln IDs
-
- V-288264
- Rule IDs
-
- SV-288264r1252959_rule
Checks: C-92948r1252375_chk
Review the application documentation and deployed configuration to determine whether the application dynamically associates security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined. If the application does not dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined, this is a finding.
Fix: F-92853r1252376_fix
Configure the application to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- GAPP-00-001310
- Vuln IDs
-
- V-288265
- Rule IDs
-
- SV-288265r1252960_rule
Checks: C-92949r1252378_chk
Review the application documentation and deployed configuration to determine whether the application enforces approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies. If the application does not enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies, this is a finding.
Fix: F-92854r1252379_fix
Configure the application to enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- GAPP-00-001320
- Vuln IDs
-
- V-288266
- Rule IDs
-
- SV-288266r1252961_rule
Checks: C-92950r1252381_chk
Review the application documentation and deployed configuration to determine whether the application enforces approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies. If the application does not enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies, this is a finding.
Fix: F-92855r1252382_fix
Configure the application to enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.
- RMF Control
- SC-16
- Severity
- M
- CCI
- CCI-001157
- Version
- GAPP-00-001330
- Vuln IDs
-
- V-288267
- Rule IDs
-
- SV-288267r1252386_rule
Checks: C-92951r1252384_chk
Review the application documentation and deployed configuration to determine whether the application associates organization-defined security attributes with information exchanged between information systems. If the application does not associate organization-defined security attributes with information exchanged between information systems, this is a finding.
Fix: F-92856r1252385_fix
Configure the application to associate organization-defined security attributes with information exchanged between information systems.
- RMF Control
- AC-16
- Severity
- M
- CCI
- CCI-002272
- Version
- GAPP-00-001340
- Vuln IDs
-
- V-288268
- Rule IDs
-
- SV-288268r1252962_rule
Checks: C-92952r1252387_chk
Review the application documentation and deployed configuration to determine whether the application dynamically associates security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined. If the application does not dynamically associate security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined, this is a finding.
Fix: F-92857r1252388_fix
Configure the application to dynamically associate security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-002205
- Version
- GAPP-00-001350
- Vuln IDs
-
- V-288269
- Rule IDs
-
- SV-288269r1252963_rule
Checks: C-92953r1252390_chk
Review the application documentation and deployed configuration to determine whether the application uniquely identifies and authenticates source points by organization, system, application, and/or individual for information transfer. If the application does not uniquely identify and authenticate source points by organization, system, application, and/or individual for information transfer, this is a finding.
Fix: F-92858r1252391_fix
Configure the application to uniquely identify and authenticate source points by organization, system, application, and/or individual for information transfer.
- RMF Control
- Severity
- M
- CCI
- CCI-004906
- Version
- GAPP-00-001360
- Vuln IDs
-
- V-288270
- Rule IDs
-
- SV-288270r1252964_rule
Checks: C-92954r1252393_chk
Review the application documentation and deployed configuration to determine whether the application implements organization-defined mechanisms or techniques to bind security attributes to transmitted information. If the application does not implement organization-defined mechanisms or techniques to bind security attributes to transmitted information, this is a finding.
Fix: F-92859r1252394_fix
Configure the application to implement organization-defined mechanisms or techniques to bind security attributes to transmitted information.
- RMF Control
- Severity
- M
- CCI
- CCI-004544
- Version
- GAPP-00-001370
- Vuln IDs
-
- V-288271
- Rule IDs
-
- SV-288271r1252965_rule
Checks: C-92955r1252396_chk
Review the application documentation and deployed configuration to determine whether the application attaches data tags containing organization-defined authorized processing to organization-defined elements of PII. If the application does not attach data tags containing organization-defined authorized processing to organization-defined elements of PII, this is a finding.
Fix: F-92860r1252397_fix
Configure the application to attach data tags containing organization-defined authorized processing to organization-defined elements of PII.
- RMF Control
- Severity
- M
- CCI
- CCI-004558
- Version
- GAPP-00-001380
- Vuln IDs
-
- V-288272
- Rule IDs
-
- SV-288272r1252966_rule
Checks: C-92956r1252399_chk
Review the application documentation and deployed configuration to determine whether the application attaches data tags containing organization-defined processing purposes to organization-defined elements of PII. If the application does not attach data tags containing organization-defined processing purposes to organization-defined elements of PII.
Fix: F-92861r1252400_fix
Configure the application to attach data tags containing organization-defined processing purposes to organization-defined elements of PII.
- RMF Control
- Severity
- M
- CCI
- CCI-003650
- Version
- GAPP-00-001390
- Vuln IDs
-
- V-288273
- Rule IDs
-
- SV-288273r1252967_rule
Checks: C-92957r1252402_chk
Review the application documentation and deployed configuration to determine whether the application enforces attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions. If the application does not enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions, this is a finding.
Fix: F-92862r1252403_fix
Configure the application to enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- GAPP-00-001400
- Vuln IDs
-
- V-288274
- Rule IDs
-
- SV-288274r1252407_rule
Checks: C-92958r1252405_chk
Review the application documentation and deployed configuration to determine whether the application identifies prohibited mobile code. If the application does not identify prohibited mobile code, this is a finding.
Fix: F-92863r1252406_fix
Configure the application to identify prohibited mobile code.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- GAPP-00-001410
- Vuln IDs
-
- V-288275
- Rule IDs
-
- SV-288275r1252410_rule
Checks: C-92959r1252408_chk
Review the application documentation and deployed configuration to determine whether the application prompts the user for action prior to executing mobile code. If the application does not prompt the user for action prior to executing mobile code, this is a finding.
Fix: F-92864r1252409_fix
Configure the application to prompt the user for action prior to executing mobile code.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- GAPP-00-001420
- Vuln IDs
-
- V-288276
- Rule IDs
-
- SV-288276r1252413_rule
Checks: C-92960r1252411_chk
Review the application documentation and deployed configuration to determine whether the application prevents the execution of prohibited mobile code. If the application does not prevent the execution of prohibited mobile code, this is a finding.
Fix: F-92865r1252412_fix
Configure the application to prevent the execution of prohibited mobile code.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- GAPP-00-001430
- Vuln IDs
-
- V-288277
- Rule IDs
-
- SV-288277r1252416_rule
Checks: C-92961r1252414_chk
Review the application documentation and deployed configuration to determine whether the application blocks, quarantines, and/or alerts administrators when prohibited mobile code is identified. If the application does not block, quarantine, and/or alert administrators when prohibited mobile code is identified, this is a finding.
Fix: F-92866r1252415_fix
Configure the application to block, quarantine, and/or alert administrators when prohibited mobile code is identified.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001169
- Version
- GAPP-00-001440
- Vuln IDs
-
- V-288278
- Rule IDs
-
- SV-288278r1252419_rule
Checks: C-92962r1252417_chk
Review the application documentation and deployed configuration to determine whether the application prevents the download of prohibited mobile code. If the application does not prevent the download of prohibited mobile code, this is a finding.
Fix: F-92867r1252418_fix
Configure the application to prevent the download of prohibited mobile code.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- GAPP-00-001450
- Vuln IDs
-
- V-288279
- Rule IDs
-
- SV-288279r1252422_rule
Checks: C-92963r1252420_chk
Review the application documentation and deployed configuration to determine whether the application prevents the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code runtime environments, and mobile agent systems. If the application does not prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code runtime environments, and mobile agent systems, this is a finding.
Fix: F-92868r1252421_fix
Configure the application to prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code runtime environments, and mobile agent systems.
- RMF Control
- MA-3
- Severity
- M
- CCI
- CCI-000870
- Version
- GAPP-00-001460
- Vuln IDs
-
- V-288280
- Rule IDs
-
- SV-288280r1252425_rule
Checks: C-92964r1252423_chk
Review the anti-malware application documentation and deployed configuration to determine whether all media used for system maintenance is scanned prior to use. If the anti-malware application does not scan all media used for system maintenance prior to use, this is a finding.
Fix: F-92869r1252424_fix
Configure the anti-malware application to scan all media used for system maintenance prior to use.
- RMF Control
- Severity
- M
- CCI
- CCI-004964
- Version
- GAPP-00-001470
- Vuln IDs
-
- V-288281
- Rule IDs
-
- SV-288281r1252428_rule
Checks: C-92965r1252426_chk
Review the anti-malware application documentation and deployed configuration to determine whether malicious code protection mechanisms are automatically updated whenever new releases are available in accordance with organizational configuration management policy. If the anti-malware application automatically update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy, this is a finding.
Fix: F-92870r1252427_fix
Configure the anti-malware application to automatically update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- GAPP-00-001480
- Vuln IDs
-
- V-288282
- Rule IDs
-
- SV-288282r1252431_rule
Checks: C-92966r1252429_chk
Review the anti-malware application documentation and deployed configuration to determine whether periodic scans of the information system are performed every seven days. If the anti-malware application malicious code protection mechanisms are not configured to perform periodic scans of the information system every seven days, this is a finding.
Fix: F-92871r1252430_fix
Configure the anti-malware application to perform periodic scans of the information system every seven days.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-002624
- Version
- GAPP-00-001490
- Vuln IDs
-
- V-288283
- Rule IDs
-
- SV-288283r1252434_rule
Checks: C-92967r1252432_chk
Review the anti-malware application documentation and deployed configuration to determine whether real-time malicious code protection scans are performed on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. If the anti-malware application malicious code protection mechanisms are not configured to perform periodic real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy, this is a finding.
Fix: F-92872r1252433_fix
Configure the anti-malware application to perform real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- GAPP-00-001500
- Vuln IDs
-
- V-288284
- Rule IDs
-
- SV-288284r1252437_rule
Checks: C-92968r1252435_chk
Review the anti-malware application documentation and deployed configuration to determine whether malicious code is blocked and quarantined upon detection. If the anti-malware application malicious code protection mechanisms are not configured to block and quarantine malicious code upon detection, this is a finding.
Fix: F-92873r1252436_fix
Configure the anti-malware application to block and quarantine malicious code upon detection.
- RMF Control
- Severity
- M
- CCI
- CCI-004963
- Version
- GAPP-00-001510
- Vuln IDs
-
- V-288285
- Rule IDs
-
- SV-288285r1252440_rule
Checks: C-92969r1252438_chk
Review the anti-malware application documentation and deployed configuration to determine whether nonsignature-based malicious code detection mechanisms are implemented. If the anti-malware application does not implement nonsignature-based malicious code detection mechanisms, this is a finding.
Fix: F-92874r1252439_fix
Configure the anti-malware application to implement nonsignature-based malicious code detection mechanisms.
- RMF Control
- Severity
- M
- CCI
- CCI-004966
- Version
- GAPP-00-001520
- Vuln IDs
-
- V-288286
- Rule IDs
-
- SV-288286r1253078_rule
Checks: C-92970r1252441_chk
Review the anti-malware application documentation and deployed configuration to determine whether alerts are sent to organization-defined personnel in response to malicious code detection. If the anti-malware application malicious code protection mechanisms are not configured send alerts to organization-defined personnel in response to malicious code detection, this is a finding.
Fix: F-92875r1252442_fix
Configure the anti-malware application to send alerts to organization-defined personnel in response to malicious code detection.
- RMF Control
- SI-8
- Severity
- M
- CCI
- CCI-001308
- Version
- GAPP-00-001530
- Vuln IDs
-
- V-288287
- Rule IDs
-
- SV-288287r1252977_rule
Checks: C-92971r1252444_chk
Review the anti-malware application documentation and deployed configuration to determine whether spam protection mechanisms are updated automatically. If the anti-malware application spam protection mechanisms are not configured to be updated automatically, this is a finding.
Fix: F-92876r1252976_fix
Configure the anti-malware application spam protection mechanisms to update automatically.
- RMF Control
- Severity
- M
- CCI
- CCI-003992
- Version
- GAPP-00-001540
- Vuln IDs
-
- V-288288
- Rule IDs
-
- SV-288288r1252449_rule
Checks: C-92972r1252447_chk
Review the application documentation and deployed configuration to determine whether the application prevents the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization. If the application does not prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.
Fix: F-92877r1252448_fix
Configure the application to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002617
- Version
- GAPP-00-001550
- Vuln IDs
-
- V-288289
- Rule IDs
-
- SV-288289r1252452_rule
Checks: C-92973r1252450_chk
Review the application documentation and deployed configuration to determine whether the application removes organization-defined software components after updated versions have been installed. If the application does not remove organization-defined software components after updated versions have been installed, this is a finding.
Fix: F-92878r1252451_fix
Configure the application to remove organization-defined software components after updated versions have been installed.
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- GAPP-00-001560
- Vuln IDs
-
- V-288290
- Rule IDs
-
- SV-288290r1252494_rule
Checks: C-92974r1252453_chk
Review the application documentation and deployed configuration to determine whether the application installs security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs). If the application does not install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs), this is a finding.
Fix: F-92879r1252454_fix
Configure the application to install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).
- RMF Control
- SI-7
- Severity
- M
- CCI
- CCI-002740
- Version
- GAPP-00-001570
- Vuln IDs
-
- V-288291
- Rule IDs
-
- SV-288291r1252458_rule
Checks: C-92975r1252456_chk
Review the application documentation and deployed configuration to determine whether the application implements cryptographic mechanisms to authenticate organization-defined software or firmware components prior to installation. If the application does not implement cryptographic mechanisms to authenticate organization-defined software or firmware components prior to installation, this is a finding.
Fix: F-92880r1252457_fix
Configure the application to install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- GAPP-00-001580
- Vuln IDs
-
- V-288292
- Rule IDs
-
- SV-288292r1252461_rule
Checks: C-92976r1252459_chk
Review the application documentation and deployed configuration to determine whether the application disables organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure. If the application does not disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure, this is a finding.
Fix: F-92881r1252460_fix
Configure the application to disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- GAPP-00-001590
- Vuln IDs
-
- V-288293
- Rule IDs
-
- SV-288293r1252464_rule
Checks: C-92977r1252462_chk
Review the application documentation and deployed configuration to determine whether the application prohibits or restricts the use of protocols that transmit unencrypted authentication information or uses flawed cryptographic algorithms for transmission. If the application does not prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithms for transmission, this is a finding.
Fix: F-92882r1252463_fix
Configure the application to prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithms for transmission.
- RMF Control
- Severity
- M
- CCI
- CCI-004922
- Version
- GAPP-00-001600
- Vuln IDs
-
- V-288294
- Rule IDs
-
- SV-288294r1252897_rule
Checks: C-92978r1252895_chk
Navigate to the time configuration function within the application. Verify the application is configured use to the system (operating system) clock. Otherwise, this is a finding.
Fix: F-92883r1252896_fix
Navigate to the time configuration function within the application. Configure the application to use the system (operating system) clock.
- RMF Control
- SA-22
- Severity
- H
- CCI
- CCI-003376
- Version
- GAPP-00-001610
- Vuln IDs
-
- V-288295
- Rule IDs
-
- SV-288295r1252470_rule
Checks: C-92979r1252468_chk
Review the application documentation and deployed configuration to determine whether the version the application running on the system is supported by the vendor. If the version of the application running on the system is not supported by the vendor, this is a finding.
Fix: F-92884r1252469_fix
Upgrade to a supported version of the application.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- GAPP-00-001620
- Vuln IDs
-
- V-288296
- Rule IDs
-
- SV-288296r1252473_rule
Checks: C-92980r1252471_chk
This requirement can be used as a bucket to disable functions within an application deemed unnecessary for the DoW mission. Review the application documentation and deployed configuration to determine whether the application is configured to disable nonessential functions. If the application does not disable nonessential functions, this is a finding.
Fix: F-92885r1252472_fix
Configure the application to disable nonessential functions.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- GAPP-00-001630
- Vuln IDs
-
- V-288297
- Rule IDs
-
- SV-288297r1252970_rule
Checks: C-92981r1252969_chk
This is a placeholder for best-practice security configurations not addressed via the other IA Controls and CCIs in this document. These instances are rare, and this must only be used in a STIG when a better control match cannot be found and best security practices are being leveraged. If this control is not required, this requirement is Not Applicable.
Fix: F-92886r1252475_fix
Tie the pertinent requirement to an appropriate IA control.