Skip to main content
CUI

Documentation - V-222665

V-222665

Application Security and Development Security Technical Implementation Guide

CAT II

Title

The designer must ensure uncategorized or emerging mobile code is not used in applications.

Description

<VulnDiscussion>By definition, mobile code is software obtained from remote systems outside the enclave boundary, transferred across a network, and then downloaded and executed on a local system without explicit installation or execution by the recipient. For a complete list of mobile code categorizations, refer to the overview document included with this STIG. Categorized mobile code includes but is not limited to: - ActiveX - Windows Scripting Host when used as mobile code - Unix Shell Scr...

Fix Text (Documentation Requirement)

Remove uncategorized or emerging mobile code from the application or obtain a waiver and risk acceptance to operate.

Documentation Status

Cancel
CUI