Skip to content

App SRG: Application Server Security Requirements Guide

This Application Server Security Requirements Guide (SRG) addresses the software framework used to create an application-server implementation, without regard to what the application functions are. The framework is comprised of services such as data connection services, security, transaction support, load balancing, management, and APIs to extend the application server. Specific software technologies used within the application server, e.g., web server, database, auditing system, etc., must meet the requirements for the specific technology SRG and/or STIG.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-APP-000497-CTR-001245

    The container platform must generate audit records when successful/unsuccessful attempts to modify security levels occur.
  • SRG-APP-000498-CTR-001250

    The container platform must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification ...
  • SRG-APP-000499-CTR-001255

    The container platform must generate audit records when successful/unsuccessful attempts to delete privileges occur.
  • SRG-APP-000500-CTR-001260

    The container platform must generate audit records when successful/unsuccessful attempts to delete security levels occur.
  • SRG-APP-000501-CTR-001265

    The container platform must generate audit records when successful/unsuccessful attempts to delete security objects occur.
  • SRG-APP-000502-CTR-001270

    The container platform must generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification ...
  • SRG-APP-000503-CTR-001275

    The container platform must generate audit records when successful/unsuccessful logon attempts occur.
  • SRG-APP-000504-CTR-001280

    The container platform must generate audit record for privileged activities.
  • SRG-APP-000505-CTR-001285

    The container platform audit records must record user access start and end times.
  • SRG-APP-000506-CTR-001290

    The container platform must generate audit records when concurrent logons from different workstations and systems occur.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules