Check: SRG-APP-000064-MAPP-NA
Mobile Application SRG:
SRG-APP-000064-MAPP-NA
(in version v1 r1)
Title
Applications must be able to function within separate processing domains (virtualized systems), when specified, so as to enable finer-grained allocation of user privileges. (Cat II impact)
Discussion
Applications must employ the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. Employing virtualization techniques to allow greater privilege within a virtual machine, while restricting privilege to the underlying actual machine is an example of providing separate processing domains for finer-grained allocation of user privileges. Rationale for non-applicability: This control is best implemented by the virtualization technology and not through each mobile application. Mobile applications are written to run on specified operating systems. If these operating systems are virtualized correctly, the mobile application would also function in that environment.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46538r1_rule
Vulnerability ID: V-35251
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000226 |
The information system provides the capability for a privileged administrator to configure organization-defined security policy filters to support different security policies. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |