UCF STIG Viewer Logo

The application must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).


Overview

Finding ID Version Rule ID IA Controls Severity
V-35401 SRG-APP-000148-MAPP-NA SV-46688r1_rule Medium
Description
To assure accountability and prevent unauthorized access, organizational users shall be identified and authenticated. Organizational users include organizational employees or individuals the organization deems to have equivalent status of employees (e.g., contractors, guest researchers, individuals from allied nations). Users (and any processes acting on behalf of users) are uniquely identified and authenticated for all accesses other than those accesses explicitly identified and documented by the organization which outlines specific user actions that can be performed on the information system without identification or authentication. Rationale for non-applicability: An assumption of this SRG is that a single user will be operating the mobile device, eliminating the need to uniquely authenticate organizational users. If a local application interacts with a remote enterprise application, the remote application will perform the authentication transaction. Permitting the local application to perform the authentication on behalf of the remote application would be an improper delegation of trust.
STIG Date
Mobile Application Security Requirements Guide 2013-01-04

Details

Check Text ( C-43756r1_chk )
This requirement is NA for the MAPP SRG.
Fix Text (F-39947r1_fix)
The requirement is NA. No fix is required.