Check: SRG-APP-000006-MAPP-00001
Mobile Application SRG:
SRG-APP-000006-MAPP-00001
(in version v1 r1)
Title
The mobile application must store an associated data attribute corresponding to the highest classification of data in the file it stores classified data. (Cat I impact)
Discussion
A classification attribute assures the data is correctly handled and processed according to its sensitivity. If the classification attribute is missing, then there is risk to data misclassification which could result in a data spill. This control greatly reduces the risk of misclassification that can result in data leaks and spillage.
Check Content
For applications that store a single classification of data or have multiple personas, this check does not apply. For applications that store classified data, perform a static program analysis of the application software to assess if the highest data classification attribute is automatically or manually created. If the supporting code is not present, this is a finding.
Fix Text
Modify code to enable the creation and storage of a highest data classification attribute.
Additional Identifiers
Rule ID: SV-46370r1_rule
Vulnerability ID: V-35083
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001399 |
The information system supports and maintains the binding of organization-defined security attributes to information in storage. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |