Check: SRG-APP-000289-MAPP-NA
Mobile Application SRG:
SRG-APP-000289-MAPP-NA
(in version v1 r1)
Title
The application must either implement compensating security controls or the organization explicitly accepts the risk of not performing the verification as required. (Cat II impact)
Discussion
Application security functional testing involves testing the application for conformance to the applications security function specifications, as well as, for the underlying security model. The need to verify security functionality applies to all security functions. The conformance criteria state the conditions necessary for the application to exhibit the desired security behavior or satisfy a security property for example, successful login triggers an audit entry. Organizations may define conditions requiring verification and the frequency in which such testing occurs. Security function testing usually occurs during the development phase and can in some instances occur in the production phase if the developer provides the security conformance criteria or if the conformance criteria can be established. There are application testing frameworks available that can perform functional testing on production systems however they are limited in their applicability and are language or product centric. Rationale for non-applicability: An assumption of this SRG is that the controls delineated in this SRG reduce risk to an acceptable level and that additional compensating controls are not required. Defense in depth is also provided by controls in the MOS SRG and MDM SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-47013r1_rule
Vulnerability ID: V-35726
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001291 |
The information system verifies the correct operation of security functions in accordance with organization-defined conditions and in accordance with organization-defined frequency (if periodic verification). |
Controls
Number | Title |
---|---|
No controls are assigned to this check |