Check: SRG-APP-000069-AS-000036
Application Server SRG:
SRG-APP-000069-AS-000036
(in versions v3 r4 through v2 r2)
Title
The application server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access. (Cat II impact)
Discussion
To establish acceptance of system usage policy, a click-through banner at the application server management interface logon is required. The banner shall prevent further activity on the application server unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK".
Check Content
Review application server management interface product documentation and configuration to determine that the logon banner can be displayed until the user takes action to acknowledge the agreement. If the banner screen allows continuation to the application server without user interaction, this is a finding.
Fix Text
Configure the application server management interface to retain the logon banner on the screen until the user takes explicit action to logon to the server.
Additional Identifiers
Rule ID: SV-204714r879548_rule
Vulnerability ID: V-204714
Group Title: SRG-APP-000069
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000050 |
The information system retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system. |
Controls
Number | Title |
---|---|
AC-8 |
System Use Notification |