From Application Security and Development Security Technical Implementation Guide
Part of ASDV-PL-003260
Associated with: CCI-003374
When maintenance no longer exists for an application, there are no individuals responsible for making security updates. The application support staff should maintain procedures for decommissioning. The decommissioning process should include notifying users of the pending decommissioning event. If the users are not informed of the decommissioning event, attackers may be able to stand up similar looking system and fool users into attempting to log onto a duplicate system. This can be as simple as a banner informing users.
Interview the application representative to determine if provisions are in place to notify users when an application is decommissioned. If provisions are not in place to notify users when an application is decommissioned, this is a finding.
Create and establish procedures to notify users when an application is decommissioned.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer