SRG-APP-000251 Controls

STIG IDVersionTitleProduct
SRG-APP-000251-API-000525V1R1The API must specify allowed origins when using Cross-Origin Resource Sharing (CORS).Security Requirements Guide - API
SRG-APP-000251-DNS-000037V4R2The DNS server implementation must check the validity of all data inputs except those specifically identified by the organization.Security Requirements Guide - Domain Name Service
SRG-APP-000251-MFP-000328V3R4The Mainframe Product must check the validity of all data inputs except those specifically identified by the organization.Security Requirements Guide - Mainframe Product
SRG-APP-000251-WSR-000157V4R4The web server must limit the character set used for data entry.Security Requirements Guide - Web Server
SRG-APP-000251-WSR-000194V4R4The web server must interpret and normalize ambiguous HTTP requests or terminate the TCP connection.Security Requirements Guide - Web Server
SRG-APP-000251-WSR-000195V4R4The web server must terminate the connection if server-level exceptions are triggered when handling requests to prevent HTTP request smuggling attacks.Security Requirements Guide - Web Server