New IP addresses, data services, and associated ports used by the application must be submitted to the appropriate approving authority for the organization, which in turn will be submitted through the DoD Ports, Protocols, and Services Management (DoD PPSM).

From Application Security and Development Security Technical Implementation Guide

Part of ASDV-PL-002980

Associated with: CCI-000388

SV-84935r1_rule New IP addresses, data services, and associated ports used by the application must be submitted to the appropriate approving authority for the organization, which in turn will be submitted through the DoD Ports, Protocols, and Services Management (DoD PPSM).

Vulnerability discussion

Failure to comply with DoD Ports, Protocols, and Services (PPS) Vulnerability Analysis and associated PPS mitigations may result in compromise of enclave boundary protections and/or functionality of the application.

Check content

All application ports, protocols, and services needed for application operation need to be in compliance with the DoD Ports and Protocols guidance. Check: http://iase.disa.mil/ppsm/Pages/index.aspx to verify the ports, protocols, and services are in compliance with the PPS CAL. Check all necessary ports and protocols needed for application operation (only those accessed from outside the local enclave) are checked against the DoD Ports and Protocols guidance to ensure compliance. Identify the ports needed for the application: - Look at System Security Plan/Accreditation documentation - Ask System Administrator - Go to Network Administrator - Go to Network Reviewer - If a network scan is available, use it - Use netstat/task manager - Check /etc./services If the application is not in compliance with DoD Ports and Protocols guidance, this is a finding.

Fix text

Verify the accreditation documentation lists all interfaces and the ports, protocols, and services used. Verify that all ports, protocols, and services are used in accordance with the DoD PPSM.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer