Check: SRG-APP-000390-AS-000254
Application Server SRG:
SRG-APP-000390-AS-000254
(in versions v3 r4 through v2 r2)
Title
The application server must require devices to re-authenticate when organization-defined circumstances or situations require re-authentication. (Cat II impact)
Discussion
Without re-authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. In addition to the re-authentication requirements associated with session locks, organizations may require re-authentication of devices, including (but not limited to), the following other situations. (i) When authenticators change; (ii) When roles change; (iii) When security categories of information systems change; (iv) After a fixed period of time; or (v) Periodically. For distributed architectures (e.g., service-oriented architectures), the decisions regarding the validation of identification claims may be made by services separate from the services acting on those decisions. In such situations, it is necessary to provide the identification decisions (as opposed to the actual identifiers) to the services that need to act on those decisions.
Check Content
Review the application server documentation and configuration to determine if the application server requires devices to re-authenticate when organization-defined circumstances or situations require re-authentication. If the application server does not require a device to re-authenticate, this is a finding.
Fix Text
Configure the application server to require devices to re-authenticate when organization-defined circumstances or situations require re-authentication.
Additional Identifiers
Rule ID: SV-204799r879763_rule
Vulnerability ID: V-204799
Group Title: SRG-APP-000390
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002039 |
The organization requires devices to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |
Controls
Number | Title |
---|---|
IA-11 |
Re-Authentication |