Check: SRG-APP-000037-MAPP-NA
Mobile Application SRG:
SRG-APP-000037-MAPP-NA
(in version v1 r1)
Title
The application must prevent access to organization-defined security-relevant information except during secure, non-operable system states. (Cat II impact)
Discussion
Security-relevant information is any information within the information system that can potentially impact the operation of security functions in a manner possibly resulting in failure to enforce the system security policy or maintain isolation of code and data. Organizations may define specific security relevant information requiring protection. Filtering rules for routers and firewalls, cryptographic key management information, key configuration parameters for security services, and access control lists are examples of security-relevant information. Secure, non-operable system states are states in which the information system is not performing mission/business-related processing (e.g., the system is off-line for maintenance, troubleshooting, boot-up, shutdown). Access to these types of data is to be prevented unless the system is in a maintenance mode or has otherwise been brought off-line. The goal is to minimize the potential a security configuration or data may be dynamically and perhaps, surreptitiously overwritten or changed (without going through a formal system change process that can document the changes). Rationale for non-applicability: Mobile applications that provide flow control or inter-domain communication are outside the scope of this SRG. Any controls that manage the dissemination of secure data within a system are covered by relevant SRGs and STIGs. At the device level, local interprocess communication is a core operating system function; OS security controls will preside over application-level controls in the event an application is taken over by a malicious user.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46460r1_rule
Vulnerability ID: V-35173
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000024 |
The information system prevents access to organization-defined security-relevant information except during secure, non-operable system states. |
Controls
Number | Title |
---|---|
AC-3 (5) |
Security-Relevant Information |