Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • Application servers must use NIST-approved or NSA-approved key management technology and processes.

    <VulnDiscussion>An asymmetric encryption key must be protected during transmission. The public portion of an asymmetric key pair can be freel...
    Rule Medium Severity
  • SRG-APP-000514

    <GroupDescription></GroupDescription>
    Group
  • The application server must use DoD- or CNSS-approved PKI Class 3 or Class 4 certificates.

    &lt;VulnDiscussion&gt;Class 3 PKI certificates are used for servers and software signing rather than for identifying individuals. Class 4 certifica...
    Rule Medium Severity
  • SRG-APP-000515

    <GroupDescription></GroupDescription>
    Group
  • The application server must, at a minimum, transfer the logs of interconnected systems in real time, and transfer the logs of standalone systems weekly.

    &lt;VulnDiscussion&gt;Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Protecting log data is ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules