Skip to content

Application Security and Development Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Unnecessary built-in application accounts must be disabled.

    <VulnDiscussion>Default passwords and properties of built-in accounts are often publicly available. Anyone with necessary knowledge, internal...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • Default passwords must be changed.

    &lt;VulnDiscussion&gt;Default passwords can easily be compromised by attackers allowing immediate access to the applications.&lt;/VulnDiscussion&gt...
    Rule High Severity
  • The designer must ensure uncategorized or emerging mobile code is not used in applications.

    &lt;VulnDiscussion&gt;By definition, mobile code is software obtained from remote systems outside the enclave boundary, transferred across a networ...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules