Check: SRG-APP-000205-MAPP-NA
Mobile Application SRG:
SRG-APP-000205-MAPP-NA
(in version v1 r1)
Title
Applications must support organizational requirements to issue public key certificates under an appropriate certificate policy or obtain public key certificates under an appropriate certificate policy from an approved service provider. (Cat II impact)
Discussion
For user certificates, each organization attains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice. This control focuses on certificates with a visibility external to the information system and does not include certificates related to internal system operations, for example, application-specific time services. Rationale for non-applicability: The issuance of public key certificates is a server function. Server applications are outside the scope of this SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46823r1_rule
Vulnerability ID: V-35536
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001159 |
Issue public key certificates under an organization-defined certificate policy or obtain public key certificates from an approved service provider. |
Controls
Number | Title |
---|---|
SC-17 |
Public Key Infrastructure Certificates |