Skip to content

App SRG: Application Server Security Requirements Guide

This Application Server Security Requirements Guide (SRG) addresses the software framework used to create an application-server implementation, without regard to what the application functions are. The framework is comprised of services such as data connection services, security, transaction support, load balancing, management, and APIs to extend the application server. Specific software technologies used within the application server, e.g., web server, database, auditing system, etc., must meet the requirements for the specific technology SRG and/or STIG.

Scheme
public.cyber.mil /stigs/downloads/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • SRG-APP-000507-CTR-001295

    The container platform runtime must generate audit records when successful/unsuccessful attempts to access objects occur.
  • SRG-APP-000508-CTR-001300

    Direct access to the container platform must generate audit records.
  • SRG-APP-000509-CTR-001305

    The container platform must generate audit records for all account creations, modifications, disabling, and termination events.
  • SRG-APP-000510-CTR-001310

    The container runtime must generate audit records for all container execution, shutdown, restart events, and program initiations.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules