Check: SRG-APP-000288-MAPP-NA
Mobile Application SRG:
SRG-APP-000288-MAPP-NA
(in version v1 r1)
Title
The application must enforce organizational requirements to protect information obtained from intrusion monitoring tools from unauthorized access, modification, and deletion. (Cat II impact)
Discussion
Intrusion monitoring applications are by their nature designed to monitor and record network and system traffic and activity. They can accumulate a significant amount of sensitive data, examples of which could include user account information and application data not related to the intrusion monitoring application itself. Intrusion monitoring tools also obtain information that is critical to conducting forensic analysis on attacks occurring within the network. This data may be sensitive in nature. Information obtained by intrusion monitoring applications in the course of evaluating network and system security needs to be protected. Rationale for non-applicability: Intrusion monitoring tools are not within the scope of this SRG. The MDM SRG addresses mechanisms that check the integrity of the mobile device.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-47012r1_rule
Vulnerability ID: V-35725
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001269 |
The organization protects information obtained from intrusion monitoring tools from unauthorized access, modification, and deletion. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |