STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288272

CAT II (Medium)

The application must attach data tags containing organization-defined processing purposes to organization-defined elements of personally identifiable information (PII).

Rule ID

SV-288272r1252966_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-004558CCI-000366

Discussion

Data tags support the tracking of processing purposes by conveying the purposes along with the relevant elements of PII throughout the system. By conveying the processing purposes in a data tag along with the personally identifiable information as the information transits a system, a system owner or operator can identify whether a change in processing would be compatible with the identified and documented purposes. Data tags may also support the use of automated tools. This requirement pertains to Zero Trust.

Check Content

Review the application documentation and deployed configuration to determine whether the application attaches data tags containing organization-defined processing purposes to organization-defined elements of PII.

If the application does not attach data tags containing organization-defined processing purposes to organization-defined elements of PII.

Fix Text

Configure the application to attach data tags containing organization-defined processing purposes to organization-defined elements of PII.