STIGQter STIGQter: STIG Summary: Test and Development Zone D Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 26 Oct 2018:

The organization must create a policy and procedures document for proper handling and transport of data entering (physically or electronically) the test and development environment.

DISA Rule

SV-56070r1_rule

Vulnerability Number

V-43317

Group Title

ENTD0370 - Policy and procedures document not created for proper data handling.

Rule Version

ENTD0370

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create a policy for, and document the procedure of, proper handling of data transported into the test and development environment. This document must include information for physical and electronic handling and migration of data.

Check Contents

Review the organization's policies and procedures document to ensure proper handling of data being transported into the test and development environment. This document must include information for physical and electronic migration of data.

If the organization does not have a policy and procedures document created or available for review, this is a finding.

Vulnerability Number

V-43317

Documentable

False

Rule Version

ENTD0370

Severity Override Guidance

Review the organization's policies and procedures document to ensure proper handling of data being transported into the test and development environment. This document must include information for physical and electronic migration of data.

If the organization does not have a policy and procedures document created or available for review, this is a finding.

Check Content Reference

M

Target Key

1134

Comments