From Application Security and Development Security Technical Implementation Guide
Part of ASDV-PL-002995
Associated with: CCI-001795
A Configuration Management (CM) repository is used to manage application code versions and to securely store application code.
Review the application system documentation and interview the application administrator. Identify if the STIG is being applied to application developers or organizations responsible for code management or who have and operate an application CM repository. If this is not the case, the requirement is not applicable. Review CM patch management processes and procedures. Have the system and CM admins demonstrate their patch management processes and verify the system has the latest security patches applied. Review the ATO documentation and verify the system that operates the CM repository software has had all relevant STIGs applied. If CM repository is not at the latest security patch level and is not operating on a STIG compliant system, this is a finding.
Patch the CM system when new security patches are made available and apply the relevant STIGs.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer