TCAT-AS-001710 - Hosted applications must be documented in the system security plan.

Information

The ISSM/ISSO must be cognizant of all applications operating on the Tomcat server, and must address any security implications associated with the operation of the applications.

If unknown/undocumented applications are operating on the Tomcat server, these applications increase risk for the system due to not being managed, patched or monitored for unapproved activity on the system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Document the applications that have an ATO on the Tomcat server.

Retain the information in the SSP and present to the auditor in the event of a CCRI.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Tomcat_Application_Server_9_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-223007r961863_rule, STIG-ID|TCAT-AS-001710, STIG-Legacy|SV-111537, STIG-Legacy|V-102597, Vuln-ID|V-223007

Plugin: Unix

Control ID: 6fa74b6bef060ace2e5511e24985f49e2e88dd693ee04b051b859cd21ed7e8ca