The ISSO must ensure if a DoD STIG or NSA guide is not available, a third-party product will be configured by following available guidance.
An XCCDF Rule
Description
Not all COTS products are covered by a STIG. Those products not covered by a STIG, should follow commercially accepted best practices, independent testing results and vendors lock down guides and recommendations if they are available.
- ID
- SV-222627r961863_rule
- Version
- APSC-DV-002970
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the application according to the product STIG or when a STIG is not available, utilize:
- commercially accepted practices,
- independent testing results, or
- vendor literature and lock down guides.