STIGQter STIGQter: STIG Summary: Arctic Wolf CylanceON-PREM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

All associated custom applications, including API endpoints, must be inventoried and managed.

DISA Rule

SV-272642r1113686_rule

Vulnerability Number

V-272642

Group Title

SRG-APP-000516

Rule Version

CYLN-OP-001270

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Manage Custom Applications. Administrator privileges are required.

1. Log in to the admin console.
2. Navigate to Configuration >> Applications.
2a. To edit an application:
- Click the "Edit" icon.
- Update the application name or permissions.
- Click the green check to save.
2b. To remove an application:
- Click the trash can icon.
- Click "Remove Application".
2c. To view the YAML file, click the API Documentation link.

Check Contents

Review the Console Applications. Administrator privileges are required.

1. Log in to the admin console.
2. Navigate to Configuration >> Applications.
3. Review the documentation of allowed applications.
4. Review the internal documentation for the location and protection of application ID and application secret.
5. All APIs must be documented.
6. Verify that controls are in place for who has access to APIs and where YAML files are stored.

If any applications exist that are not documented, this is a finding.

If application ID and application secrets are not documented and stored in the authorized location, this is a finding.

If any APIs are in use and not documented, this is a finding.

If the location and access of YAML files are not documented, this is a finding.

If any of the above is documented but not adhered to, this is a finding.

Vulnerability Number

V-272642

Documentable

False

Rule Version

CYLN-OP-001270

Severity Override Guidance

Review the Console Applications. Administrator privileges are required.

1. Log in to the admin console.
2. Navigate to Configuration >> Applications.
3. Review the documentation of allowed applications.
4. Review the internal documentation for the location and protection of application ID and application secret.
5. All APIs must be documented.
6. Verify that controls are in place for who has access to APIs and where YAML files are stored.

If any applications exist that are not documented, this is a finding.

If application ID and application secrets are not documented and stored in the authorized location, this is a finding.

If any APIs are in use and not documented, this is a finding.

If the location and access of YAML files are not documented, this is a finding.

If any of the above is documented but not adhered to, this is a finding.

Check Content Reference

M

Target Key

5692