SRG-APP-000439 Controls

STIG IDVersionTitleProduct
SRG-APP-000439-API-001005V1R1The amount of data returned by the API must be restricted.Security Requirements Guide - API
SRG-APP-000439-API-001010V1R1The API must use TLS version 1.2 at a minimum.Security Requirements Guide - API
SRG-APP-000439-CTR-001080V2R4The application must protect the confidentiality and integrity of transmitted information.Security Requirements Guide - Container Platform
SRG-APP-000439-DNS-000063V4R2The DNS server implementation must protect the integrity of transmitted information.Security Requirements Guide - Domain Name Service
SRG-APP-000439-WSR-000151V4R4The web server must employ cryptographic mechanisms (TLS/DTLS/SSL) preventing the unauthorized disclosure of information during transmission.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000152V4R4Web server session IDs must be sent to the client using SSL/TLS.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000153V4R4Web server cookies, such as session cookies, sent to the client using SSL/TLS must not be compressed.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000154V4R4Cookies exchanged between the web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie data.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000155V4R4Cookies exchanged between the web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000156V4R4A web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000188V4R4The web server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000192V4R4The web server must use HTTP/2, at a minimum.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000193V4R4The web server must disable HTTP/1.x downgrading.Security Requirements Guide - Web Server
SRG-APP-000439-WSR-000196V4R4The web server must only use forward proxies that route HTTP/2 requests upstream.Security Requirements Guide - Web Server