Check: SRG-APP-000240-MAPP-NA
Mobile Application SRG:
SRG-APP-000240-MAPP-NA
(in version v1 r1)
Title
Applications required to be non-modifiable must support organizational requirements to provide components that contain no writeable storage capability. These components must be persistent across restart and/or power on/off. (Cat II impact)
Discussion
Organizations may require applications or application components to be non-modifiable or to be stored and executed on non-writeable storage. Use of non-modifiable storage ensures the integrity of the software program from the point of creation of the read-only image and eliminates the possibility of malicious code insertion. Rationale for non-applicability: This control conflicts with a core requirement that mobile applications be modifiable. The primary means for updating the configuration of mobile applications is to replace the entire application.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46922r1_rule
Vulnerability ID: V-35635
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001214 |
The organization employs organization-defined information system components with no writeable storage that are persistent across component restart or power on/off. |
Controls
Number | Title |
---|---|
SC-34 (1) |
No Writable Storage |