Check: ENTD0140
Test and Development Zone A STIG:
ENTD0140
(in versions v1 r6 through v1 r3)
Title
Access to source code during application development must be restricted to authorized users. (Cat II impact)
Discussion
Restricting access to source code and the application to authorized users will limit the risk of source code theft or other potential compromise.
Check Content
Review the organization's site security plan and documentation to determine whether there is a list of current authorized users. If a current list of authorized users is missing from the site security plan for the test and development environment, this is a finding. If there isn't any application development occurring in the zone environment, this requirement is not applicable.
Fix Text
Document all authorized users with access to the development environment and access to source code. If the documentation exists but is not current, bring the documentation up to date.
Additional Identifiers
Rule ID: SV-51477r1_rule
Vulnerability ID: V-39619
Group Title: ENTD0140 - Source code not restricted to authorized individuals.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |