Skip to main content
CUI

Documentation - V-222425

V-222425

Application Security and Development Security Technical Implementation Guide

CAT I

Title

The application must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Description

<VulnDiscussion>To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DoD-approved PKIs, all DoD systems (e.g., networks, web servers, and web portals) must be properly configured to incorporate access control methods that do not rely solely on the possession of a certificate for access. Successful authentication must not automatically give an entity access to a restricted asset or security boundary. Authorization procedures and...

Fix Text (Documentation Requirement)

Design or configure the application to enforce access to application resources.

Documentation Status

Cancel
CUI