Check: SRG-APP-000073-MAPP-NA
Mobile Application SRG:
SRG-APP-000073-MAPP-NA
(in version v1 r1)
Title
Applications scanning for malicious code must scan all media used for system maintenance prior to use. (Cat II impact)
Discussion
There are security-related issues arising from software brought into the information system specifically for diagnostic and repair actions. (e.g., a software packet sniffer installed on a system in order to troubleshoot system traffic, or a vendor installing or running a diagnostic application in order to troubleshoot an issue with a vendor supported system). This requirement ensures the media containing the application is scanned for malicious code prior to use. Rationale for non-applicability: Malicious code protections are within the scope of the MDM SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46548r1_rule
Vulnerability ID: V-35261
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000870 |
The organization checks media containing diagnostic and test programs for malicious code before the media are used in the information system. |
Controls
Number | Title |
---|---|
MA-3 (2) |
Inspect Media |