Check: SRG-APP-000316-AS-000199
Application Server SRG:
SRG-APP-000316-AS-000199
(in versions v3 r4 through v2 r2)
Title
The application server must provide the capability to immediately disconnect or disable remote access to the management interface. (Cat II impact)
Discussion
Without the ability to immediately disconnect or disable remote access, an attack or other compromise taking progress would not be immediately stopped. The application server must have the capability to immediately disconnect current users remotely accessing the management interface and/or disable further remote access. The speed of disconnect or disablement varies based on the criticality of missions/business functions and the need to eliminate immediate or future remote access to organizational information systems.
Check Content
Review the application server product documentation and server configuration to ensure that there is a capability to immediately disconnect or disable remote access to the management interface. If there is no capability, this is a finding.
Fix Text
Configure the application server to have the capability to immediately disconnect or disable remote access to the management interface.
Additional Identifiers
Rule ID: SV-204783r879693_rule
Vulnerability ID: V-204783
Group Title: SRG-APP-000316
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002322 |
The organization provides the capability to expeditiously disconnect or disable remote access to the information system within the organization-defined time period. |
Controls
Number | Title |
---|---|
AC-17 (9) |
Disconnect / Disable Access |