STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288292

CAT II (Medium)

The application must disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.

Rule ID

SV-288292r1252461_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-000382CCI-001762

Discussion

Removal of unneeded or nonsecure functions, ports, protocols, and services mitigate the risk of unauthorized connection of devices, unauthorized transfer of information, or other exploitation of these resources. The organization must perform a periodic scan/review of the application (as required by CCI-000384) and disable functions, ports, protocols, and services deemed to be unneeded or nonsecure.

Check Content

Review the application documentation and deployed configuration to determine whether the application disables organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.

If the application does not disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure, this is a finding.

Fix Text

Configure the application to disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.