Check: APSC-DV-003340
Application Security and Development STIG:
APSC-DV-003340
(in versions v5 r3 through v4 r2)
Title
At least one application administrator must be registered to receive update notifications, or security alerts, when automated alerts are available. (Cat III impact)
Discussion
Administrators should register for updates to all COTS and custom-developed software, so when security flaws are identified, they can be tracked for testing and updates of the application can be applied. Admin personnel should be registered to receive updates to all components of the application, such as Web Server, Application Servers, and Database Servers. Also, if update notifications are provided for any custom-developed software, libraries or third-party tools, deployment personnel must also register for these updates.
Check Content
Review the components of the application. Ask the application representative to demonstrate deployment personnel are registered to receive notifications for update notification for all of the application components including custom-developed software, libraries and third-party tools. If no deployment personnel are registered to receive the alerts, this is a finding.
Fix Text
Register administrators to receive update notifications so they can patch and update applications and application components.
Additional Identifiers
Rule ID: SV-222669r879887_rule
Vulnerability ID: V-222669
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-001285 |
The organization receives information system security alerts, advisories, and directives from organization-defined external organizations on an ongoing basis. |