Application Security and Development Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The application must implement replay-resistant authentication mechanisms for network access to privileged accounts.
A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authenticator and the application validating the user credentials must not be ...Rule Medium Severity -
SRG-APP-000157
Group -
SRG-APP-000158
Group -
SRG-APP-000394
Group -
The application must authenticate all network connected endpoint devices before establishing any connection.
Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. For distributed architectures (e.g., service-oriented architectures), th...Rule Medium Severity -
SRG-APP-000395
Group -
SRG-APP-000163
Group -
The application must disable device identifiers after 35 days of inactivity unless a cryptographic certificate is used for authentication.
Device identifiers are used to identify hardware devices that interact with the application much like a user account is used to identify an application user. Examples of hardware devices include bu...Rule Medium Severity -
SRG-APP-000164
Group -
The application must enforce a minimum 15-character password length.
The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised. Use of passwords for application authentication is intended only ...Rule High Severity -
SRG-APP-000166
Group -
SRG-APP-000167
Group -
SRG-APP-000168
Group -
SRG-APP-000169
Group -
SRG-APP-000170
Group -
The application must require the change of at least eight of the total number of characters when passwords are changed.
Use of passwords for application authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication. Examples of situations wh...Rule Medium Severity -
SRG-APP-000171
Group -
SRG-APP-000172
Group -
The application must transmit only cryptographically-protected passwords.
Use of passwords for application authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication. Examples of situations wh...Rule High Severity -
SRG-APP-000173
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.