UCF STIG Viewer Logo

Applications used for non-local maintenance sessions must protect those sessions through the use of a strong authenticator tightly bound to the user.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35509 SRG-APP-000183-MAPP-NA SV-46796r1_rule Medium
Description
Non-local maintenance and diagnostic activities are those activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network. Identification and authentication techniques used in the establishment of non-local maintenance and diagnostic sessions must be consistent with the network access requirements in IA-2. Strong authenticators include, PKI where certificates are stored on a token protected by a password, passphrase, or biometric. Examples of types of applications used for non-local maintenance and diagnostic activities are provided below. Use as an example does not imply compliance with policy requirements or approval for use. Examples include but are not limited to: - Terminal Services - Remote Desktop - Dameware - VNC (all variants). Rationale for non-applicability: Mobile applications that support remote access are not within the scope of this SRG.
STIG Date
Mobile Application Security Requirements Guide 2013-01-04

Details

Check Text ( C-43849r1_chk )
This requirement is NA for the MAPP SRG.
Fix Text (F-40050r1_fix)
The requirement is NA. No fix is required.