Check: SRG-APP-000255-MAPP-NA
Mobile Application SRG:
SRG-APP-000255-MAPP-NA
(in version v1 r1)
Title
Boundary protection applications must be capable of preventing public access into the organizations internal networks except as appropriately mediated by managed interfaces. (Cat II impact)
Discussion
Access into an organization's internal network and to key internal boundaries must be tightly controlled and managed. Applications monitoring and/or controlling communications at the external boundary of the system and at key internal boundaries must be capable of preventing public access into the organization's internal networks except as appropriately mediated by managed interfaces. Rationale for non-applicability: Mobile applications do not provide network services to other devices. Most mobile devices function outside the organization's security boundary and therefore are not positioned to provide boundary protection services in any case.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46962r1_rule
Vulnerability ID: V-35675
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001100 |
The information system prevents public access into the organization's internal networks except as appropriately mediated by managed interfaces employing boundary protection devices. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |