Check: APSC-DV-003030
Application Security and Development STIG:
APSC-DV-003030
(in versions v5 r3 through v4 r2)
Title
The application services and interfaces must be compatible with and ready for IPv6 networks. (Cat II impact)
Discussion
If the application has not been upgraded to execute on an IPv6-only network, there is a possibility the application will not execute properly, and as a result, a denial of service could occur. In order to operate on an IPV6 network, the application must be capable of making IPV6 compatible network socket calls.
Check Content
Verify the application environment is compliant with all DoD IPv6 Standards Profile for IPv6 Capable Products guidance for servers. If the application environment is not compliant with all DoD IPv6 Standards Profile for IPv6 Capable Products guidance for servers, this is a finding.
Fix Text
Design application to be compliant with all Department of Defense (DoD) Information Technology Standards Registry (DISR) IPv6 profiles.
Additional Identifiers
Rule ID: SV-222634r879760_rule
Vulnerability ID: V-222634
Group Title: SRG-APP-000387
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002853 |
The information system provides the capability to employ organization-defined alternative communications protocols in support of maintaining continuity of operations. |
Controls
Number | Title |
---|---|
CP-11 |
Alternate Communications Protocols |