Check: APSC-DV-002990
Application Security and Development STIG:
APSC-DV-002990
(in versions v5 r3 through v4 r2)
Title
The application must be registered with the DoD Ports and Protocols Database. (Cat II impact)
Discussion
Failure to register the applications usage of ports, protocols, and services with the DoD PPS Database may result in a Denial of Service (DoS) because of enclave boundary protections at other end points within the network.
Check Content
Verify registration of the application and ports in the Ports and Protocols Database for a production site. If the application requires registration, and is not registered or all ports used have not been identified in the database, this is a finding.
Fix Text
Register the application and ports in the Ports and Protocols Database.
Additional Identifiers
Rule ID: SV-222629r879887_rule
Vulnerability ID: V-222629
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-000388 |
The organization ensures compliance with organization-defined registration requirements for functions, ports, protocols, and services. |