STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288146

CAT II (Medium)

The application must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.

Rule ID

SV-288146r1252023_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-005156CCI-000366

Discussion

Identity assertions and access tokens are typically digitally signed. The private keys used to sign these assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.

Check Content

Review the application documentation and deployed configuration to determine whether the application generates, manages, and protects from disclosure and misuse the cryptographic keys that protect access tokens.

If the application does not generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens, this is a finding.

Fix Text

Configure the application to generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.