Check: SRG-APP-000283-MAPP-NA
Mobile Application SRG:
SRG-APP-000283-MAPP-NA
(in version v1 r1)
Title
Applications providing malware and/or firewall protection must monitor inbound and outbound communications for unauthorized activities or conditions. (Cat II impact)
Discussion
Unusual/unauthorized activities or conditions include internal traffic indicating the presence of malicious code within an information system or propagating among system components, the unauthorized export of information, or signaling to an external information system. Evidence of malicious code is used to identify potentially compromised information systems or information system components. Examples of applications that provide monitoring capability for unusual/unauthorized activities include, but are not limited to, Intrusion Detection, Anti-Virus and Malware etc. Rationale for non-applicability: The requirement for application sandboxing precludes applications from serving as a security boundary for other applications. If an application were granted the ability to perform this function, the mobile application could perform a man-in-the-middle attack on other applications running on the device.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-47005r1_rule
Vulnerability ID: V-35718
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001262 |
The information system monitors inbound and outbound communications for unusual or unauthorized activities or conditions. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |