Check: EMG3-045 EMail
Email Services Policy STIG:
EMG3-045 EMail
(in version v2 r6)
Title
Email Configuration Management (CM) procedures must be implemented. (Cat II impact)
Discussion
Uncontrolled, untested, or unmanaged changes can result in an unreliable security posture. All software libraries related to email services must be reviewed, considered, and the responsibility for CM assigned to ensure no libraries or configurations are left unaddressed. This is true even if CM responsibilities appear to cross organizational boundaries. Ensure patches, configurations, and upgrades are addressed. Process steps should have specific procedures and responsibilities assigned to individuals.
Check Content
Access the EDSP and confirm CM procedures and assignments are documented. Examine artifacts that show the processes have been implemented. If CM procedures are documented and implemented, this is not a finding.
Fix Text
Document Configuration Management procedures in the EDSP. Implement the CM procedures as documented.
Additional Identifiers
Rule ID: SV-20644r3_rule
Vulnerability ID: V-18864
Group Title: EMG3-045 Email Configuration Management
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |