STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288271

CAT II (Medium)

The application must attach data tags containing organization-defined authorized processing to organization-defined elements of personally identifiable information (PII).

Rule ID

SV-288271r1252965_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-004544CCI-000366

Discussion

Data tags support the tracking and enforcement of authorized processing by conveying the types of processing that are authorized along with the relevant elements of PII throughout the system. Data tags may also support the use of automated tools. This requirement pertains to Zero Trust.

Check Content

Review the application documentation and deployed configuration to determine whether the application attaches data tags containing organization-defined authorized processing to organization-defined elements of PII.

If the application does not attach data tags containing organization-defined authorized processing to organization-defined elements of PII, this is a finding.

Fix Text

Configure the application to attach data tags containing organization-defined authorized processing to organization-defined elements of PII.