SV-279056r1171606_rule
V-279056
SRG-APP-000156-AS-000106
APAS-CF-000325
CAT II
10
Configure web services using the SOAP protocol to access sensitive data.
1. Install and configure the WS-Security suite to secure access to the sensitive data.
2. Ensure the configuration provides:
- Authentication of service consumers.
- Message integrity (e.g., via XML signatures).
- Confidentiality (e.g., via encryption).
3. Update application and service documentation to reflect the WS-Security implementation.
Verify that web services using the SOAP protocol to access sensitive data are secured with WS-Security.
1. Determine Web Services Usage by interviewing the system administrator (SA), or reviewing relevant documentation, including:
- Hosted application source code.
- Application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.
2. Evaluate Applicability.
If no web services are published, this requirement is not a finding.
If web services are published and the SOAP protocol is not used, this is not a finding.
If SOAP is used and the data accessed is not sensitive, this requirement is not a finding.
3. Verify Security Controls. If web services are published using SOAP to access sensitive data:
a. Confirm that WS-Security is implemented to provide secure authentication and protect the data.
b. This may be verified by interviewing the administrator or reviewing the documentation sources listed above.
If web services are published using SOAP to access sensitive data and WS-Security is not implemented, this is a finding.
V-279056
False
APAS-CF-000325
Verify that web services using the SOAP protocol to access sensitive data are secured with WS-Security.
1. Determine Web Services Usage by interviewing the system administrator (SA), or reviewing relevant documentation, including:
- Hosted application source code.
- Application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.
2. Evaluate Applicability.
If no web services are published, this requirement is not a finding.
If web services are published and the SOAP protocol is not used, this is not a finding.
If SOAP is used and the data accessed is not sensitive, this requirement is not a finding.
3. Verify Security Controls. If web services are published using SOAP to access sensitive data:
a. Confirm that WS-Security is implemented to provide secure authentication and protect the data.
b. This may be verified by interviewing the administrator or reviewing the documentation sources listed above.
If web services are published using SOAP to access sensitive data and WS-Security is not implemented, this is a finding.
M
5724