Skip to content

Application Security and Development Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Default passwords must be changed.

    <VulnDiscussion>Default passwords can easily be compromised by attackers allowing immediate access to the applications.</VulnDiscussion&gt...
    Rule High Severity
  • An Application Configuration Guide must be created and included with the application.

    <VulnDiscussion>The Application Configuration Guide is any document or collection of documents used to configure the application. These docu...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • If the application contains classified data, a Security Classification Guide must exist containing data elements and their classification.

    &lt;VulnDiscussion&gt;Without a classification guide the marking, storage, and output media of classified material can be inadvertently mixed with ...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules