STIGQter STIGQter: STIG Summary: Application Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The application server must use an approved DOD enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate users (or processes acting on behalf of organizational users).

DISA Rule

SV-204745r1051118_rule

Vulnerability Number

V-204745

Group Title

SRG-APP-000148

Rule Version

SRG-APP-000148-AS-000101

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the application server to use an approved enterprise ICAM solution to uniquely identify and authenticate users and processes acting on behalf of organizational users.

Check Contents

Review application server documentation and configuration settings to determine if the application server is using an approved enterprise ICAM solution to authenticate organizational users and processes running on the users' behalf.

If an approved enterprise ICAM solution is not being used, this is a finding.

Note: If the site is currently using an enterprise solution (AAA Server) and has documented their plans to move to an approved enterprise ICAM solution, the severity of this control can be reduced to a CAT III.

Vulnerability Number

V-204745

Documentable

False

Rule Version

SRG-APP-000148-AS-000101

Severity Override Guidance

Review application server documentation and configuration settings to determine if the application server is using an approved enterprise ICAM solution to authenticate organizational users and processes running on the users' behalf.

If an approved enterprise ICAM solution is not being used, this is a finding.

Note: If the site is currently using an enterprise solution (AAA Server) and has documented their plans to move to an approved enterprise ICAM solution, the severity of this control can be reduced to a CAT III.

Check Content Reference

M

Target Key

2900