Application Security and Development Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The designer must ensure uncategorized or emerging mobile code is not used in applications.
<VulnDiscussion>By definition, mobile code is software obtained from remote systems outside the enclave boundary, transferred across a networ...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
Production database exports must have database administration credentials and sensitive data removed before releasing the export.
<VulnDiscussion>Production database exports are often used to populate development databases. Test and development environments do not typica...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
Protections against DoS attacks must be implemented.
<VulnDiscussion>Known DoS threats documented in the threat model should be mitigated, to prevent DoS type attacks.</VulnDiscussion><...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules