Skip to content

III - Administrative Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000456-AS-000266

    <GroupDescription></GroupDescription>
    Group
  • The MQ Appliance messaging server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

    &lt;VulnDiscussion&gt;Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products t...
    Rule Medium Severity
  • SRG-APP-000514-AS-000137

    <GroupDescription></GroupDescription>
    Group
  • The MQ Appliance messaging server must use DoD- or CNSS-approved PKI Class 3 or Class 4 certificates.

    &lt;VulnDiscussion&gt;Class 3 PKI certificates are used for servers and software signing rather than for identifying individuals. Class 4 certifica...
    Rule Medium Severity
  • SRG-APP-000435-AS-000069

    <GroupDescription></GroupDescription>
    Group
  • The MQ Appliance messaging server, when categorized as a high level system, must be in a high-availability (HA) cluster.

    &lt;VulnDiscussion&gt;A high level system is a system that handles data vital to the organization's operational readiness or effectiveness of deplo...
    Rule Medium Severity
  • SRG-APP-000014-AS-000009

    <GroupDescription></GroupDescription>
    Group
  • The MQ Appliance messaging server must use encryption strength in accordance with the categorization of the management data during remote access management sessions.

    &lt;VulnDiscussion&gt;Remote management access is accomplished by leveraging common communication protocols and establishing a remote connection to...
    Rule Medium Severity
  • SRG-APP-000515-AS-000203

    <GroupDescription></GroupDescription>
    Group
  • The MQ Appliance messaging server must, at a minimum, transfer the logs of interconnected systems in real time, and transfer the logs of standalone systems weekly.

    &lt;VulnDiscussion&gt;Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Protecting log data is ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules