UCF STIG Viewer Logo

Boundary protection applications must fail securely in the event of an operational failure.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35673 SRG-APP-000254-MAPP-NA SV-46960r1_rule Medium
Description
Fail secure is a condition achieved by the application of a set of information system mechanisms to ensure that in the event of an operational failure of a boundary protection device at a managed interface (e.g., router, firewall, guard, application gateway residing on a protected sub network commonly referred to as a demilitarized zone), the system does not enter into an unsecure state where intended security properties no longer hold. A failure of a boundary protection device cannot lead to, or cause information external to the boundary protection device to enter the device, nor can a failure permit unauthorized information release. Rationale for non-applicability: Mobile applications do not provide network services to other devices. Most mobile devices function outside the organization's security boundary and therefore are not positioned to provide boundary protection services in any case
STIG Date
Mobile Application Security Requirements Guide 2013-01-04

Details

Check Text ( C-44015r1_chk )
This requirement is NA for the MAPP SRG.
Fix Text (F-40215r1_fix)
The requirement is NA. No fix is required.