STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 23 Oct 2020:

The application must associate organization-defined types of security attributes having organization-defined security attribute values with information in process.

DISA Rule

SV-222394r508029_rule

Vulnerability Number

V-222394

Group Title

SRG-APP-000313

Rule Version

APSC-DV-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Design and configure the application to retain the data marking when processing data.

Check Contents

Review the application documentation and interview the application administrator.

Identify if the application requirements include data marking. Also determine if the application processes classified, FOUO or other data that is required to be marked.

If the application does not contain classified, FOUO or have data marking requirements, this requirement is not applicable.

Access the user interface for the application and navigate through the application. Perform several application actions that will manipulate data contained within the application.

For example, create a test record and assign a data marking to the data element. Save the test record, close the data entry fields and navigate to display the test record. Perform an edit action on the test data that does not edit the marking itself or perform any other form of data processing such as assigning the data to another users work queue for review or printing the data, ensure the data marking is retained throughout the data processing actions.

If application data required to be marked does not retain its marking while it is being processed by the application, this is a finding.

Vulnerability Number

V-222394

Documentable

False

Rule Version

APSC-DV-000120

Severity Override Guidance

Review the application documentation and interview the application administrator.

Identify if the application requirements include data marking. Also determine if the application processes classified, FOUO or other data that is required to be marked.

If the application does not contain classified, FOUO or have data marking requirements, this requirement is not applicable.

Access the user interface for the application and navigate through the application. Perform several application actions that will manipulate data contained within the application.

For example, create a test record and assign a data marking to the data element. Save the test record, close the data entry fields and navigate to display the test record. Perform an edit action on the test data that does not edit the marking itself or perform any other form of data processing such as assigning the data to another users work queue for review or printing the data, ensure the data marking is retained throughout the data processing actions.

If application data required to be marked does not retain its marking while it is being processed by the application, this is a finding.

Check Content Reference

M

Target Key

4093

Comments