Check: SRG-APP-000156-MAPP-NA
Mobile Application SRG:
SRG-APP-000156-MAPP-NA
(in version v1 r1)
Title
The application must use organization-defined replay-resistant authentication mechanisms for network access to privileged accounts. (Cat II impact)
Discussion
An authentication process resists replay attacks if it is impractical to achieve a successful authentication by recording and replaying a previous authentication message. Techniques used to address this include protocols using nonce's (e.g., numbers generated for a specific one time use) or challenges (e.g., TLS, WS_Security), and time synchronous or challenge-response one-time authenticators. Rationale for non-applicability: Mobile applications that support remote access are not within the scope of this SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46700r1_rule
Vulnerability ID: V-35413
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000774 |
The information system uses organization-defined replay-resistant authentication mechanisms for network access to privileged accounts. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |