STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 4 Release: 9 Benchmark Date: 25 Jan 2019: The application must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application.

DISA Rule

SV-83971r2_rule

Vulnerability Number

V-69349

Group Title

SRG-APP-000068

Rule Version

APSC-DV-000550

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the application to present the standard DoD-approved banner prior to granting access to the application.

Check Contents

If the application has no interactive user interface, this requirement is not applicable.

Log on to the application as a user.

Observe the screen and ensure the DoD-approved banner is displayed prior to obtaining access to the application. Refer to the vulnerability discussion for the approved text.

If the only way to access the application is through the OS console, e.g., a fat client application installed on a GFE desktop or laptop, and that GFE is configured to display the DoD banner, an additional banner is not required at the application level.

If the standard DoD-approved banner is not displayed prior to obtaining access, this is a finding.

Vulnerability Number

V-69349

Documentable

False

Rule Version

APSC-DV-000550

Severity Override Guidance

If the application has no interactive user interface, this requirement is not applicable.

Log on to the application as a user.

Observe the screen and ensure the DoD-approved banner is displayed prior to obtaining access to the application. Refer to the vulnerability discussion for the approved text.

If the only way to access the application is through the OS console, e.g., a fat client application installed on a GFE desktop or laptop, and that GFE is configured to display the DoD banner, an additional banner is not required at the application level.

If the standard DoD-approved banner is not displayed prior to obtaining access, this is a finding.

Check Content Reference

M

Target Key

3009

Comments