Application development must not occur on DoD operational network segments.

From Test and Development Zone A Security Technical Implementation Guide

Part of ENTD0060 - Development on operational network segments.

Associated with IA controls: ECSC-1

SV-51294r1_rule Application development must not occur on DoD operational network segments.

Vulnerability discussion

To reduce the risk of compromise of DoD operational networks and data, application and system development needs to be limited to systems within a network segment designated for development only.

Check content

Review the organization's network diagrams to determine whether network segments for development have been established and outlined in the documentation. If application development occurs on DoD operational networks, this is a finding. If there isn't any application development occurring in the zone environment, this requirement is not applicable.

Fix text

Designate network segments for applications and systems development. Document these designated network segments in the network diagrams for the T&D environment.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer