At least one application administrator must be registered to receive update notifications, or security alerts, when automated alerts are available.

From Application Security and Development Security Technical Implementation Guide

Part of ASDV-PL-003340

Associated with: CCI-001285

SV-85039r1_rule At least one application administrator must be registered to receive update notifications, or security alerts, when automated alerts are available.

Vulnerability discussion

Administrators should register for updates to all COTS and custom-developed software, so when security flaws are identified, they can be tracked for testing and updates of the application can be applied.Admin personnel should be registered to receive updates to all components of the application, such as Web Server, Application Servers, and Database Servers. Also, if update notifications are provided for any custom-developed software, libraries or third-party tools, deployment personnel must also register for these updates.

Check content

Review the components of the application. Ask the application representative to demonstrate deployment personnel are registered to receive notifications for update notification for all of the application components including custom-developed software, libraries and third-party tools. If no deployment personnel are registered to receive the alerts, this is a finding.

Fix text

Register administrators to receive update notifications so they can patch and update applications and application components.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer