STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288152

CAT II (Medium)

The application must time-restrict assertions in accordance with organization-defined identification and authentication policy.

Rule ID

SV-288152r1252658_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-005162CCI-000366

Discussion

In the context of authentication, an assertion is a verifiable statement from an Identity Provider (IdP) to a Relying Party (RP) that contains information about an end-user, including their authentication status and other relevant details. An assertion is essentially a message or document that the IdP (like a website or service that handles logins) sends to the RP (the application or service the user is trying to access) to confirm that a user has been authenticated. Assertions typically include information about: - User identity: The user's name, email, or other identifying attributes. - Authentication status: Whether the user has successfully logged in and the method used (e.g., password, multifactor authentication [MFA]). - Time of authentication: When the user was authenticated. - Attributes: Other relevant user data, like roles, permissions, or department affiliations.

Check Content

Review the application documentation and deployed configuration to determine whether the application time-restricts assertions in accordance with organization-defined identification and authentication policy.

If the application does not time-restrict assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Fix Text

Configure the application to time-restrict assertions in accordance with organization-defined identification and authentication policy.