STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288267

CAT II (Medium)

The application must associate organization-defined security attributes with information exchanged between information systems.

Rule ID

SV-288267r1252386_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-001157

Discussion

If security attributes are not associated with the information being transmitted between systems, access control policies and information flows that depend on these security attributes will not function, and unauthorized access may result. Security attributes are values associated with data content/structure and source/destination objects. These attributes are bound to the user and data objects and may include information about the data's purpose, creator, origin, access restrictions, access permissions, or classification. Specific security attributes used depend on the application or technology context. However, these attributes are used in information systems to implement security policy for access control and flow control for users, data, and traffic. Security attributes may be explicitly or implicitly associated with the information contained within the information system. This requirement applies to those applications that transmit or receive data between information systems.

Check Content

Review the application documentation and deployed configuration to determine whether the application associates organization-defined security attributes with information exchanged between information systems.

If the application does not associate organization-defined security attributes with information exchanged between information systems, this is a finding.

Fix Text

Configure the application to associate organization-defined security attributes with information exchanged between information systems.