Check: SRG-APP-000239-MAPP-NA
Mobile Application SRG:
SRG-APP-000239-MAPP-NA
(in version v1 r1)
Title
The application must protect the integrity of information during the processes of data aggregation, packaging, and transformation in preparation for transmission. (Cat II impact)
Discussion
Information can be subjected to unauthorized changes (e.g., malicious and/or unintentional modification) at information aggregation or protocol transformation points. It is therefore imperative the application take steps to validate and assure the integrity of data while at these stages of processing. For example, an application developer may determine based upon application requirements that various application data must accumulate in a processing queue where the application analyses, packages or transforms the data pending a data transfer. A window of time now exists where if an attacker were to gain access to the data residing in the application queue they could potentially compromise that data or alter results. The application must ensure the integrity of data that is pending transfer is maintained. If the application were to simply transmit aggregated, packaged or transformed data without ensuring the data was not manipulated during these processes, then the integrity of the data may be called into question. Rationale for non-applicability: Transformation of data inherently affects the integrity of the data inputs. Several operating system controls, including application sandboxing and white listing of applications, greatly mitigates the risk that any processes will be able to modify data in an unauthorized manner.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46918r1_rule
Vulnerability ID: V-35631
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001209 |
The information system protects the integrity of information during the processes of data aggregation, packaging, and transformation in preparation for transmission. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |