Protections against DoS attacks must be implemented.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-222667APSC-DV-003320SV-222667r961863_ruleCCI-002386medium
Description
Known DoS threats documented in the threat model should be mitigated, to prevent DoS type attacks.
STIGDate
Application Security and Development Security Technical Implementation Guide2025-09-09

Related Frameworks

6 paths across 3 frameworks
SCF4 mappings
CAP-01Capacity & Performance Management
0.50
  • DISA · V6R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
CAP-02Resource Priority
0.50
  • DISA · V6R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
CAP-03Capacity Planning
0.50
  • DISA · V6R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
NET-02.1Denial of Service (DoS) Protection
0.50
  • DISA · V6R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-531 mapping
SC-5
1.00
  • DISA · V6R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-002386
1.00
  • DISA · V6R4 · disa_xccdf · related

Details

Check Text (C-222667r961863_chk)

Ask the application representative for the threat model document. Examine the threat model document and determine if DoS attacks are specified as a threat. If there are no DoS threats identified in the threat model, the requirement is not applicable. Verify the mitigations provided for DoS attacks are implemented from the threat model. If mitigations for DoS attacks are identified in the threat model but are not implemented, this is a finding.

Fix Text (F-24326r493910_fix)

Implement mitigations from the threat model for DOS attacks.