STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288147

CAT II (Medium)

The application must protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.

Rule ID

SV-288147r1252026_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-005157CCI-000366

Discussion

This includes verification of digital signatures protecting identity assertions and access tokens, as well as included metadata. Metadata includes information about the access request such as information unique to user, system or information resource being accessed, or the transaction itself such as time. Protected system and information resources could include connected networks, applications, and Application Programming Interfaces (APIs).

Check Content

Review the application documentation and deployed configuration to determine whether the application protects the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.

If the application does not protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed, this is a finding.

Fix Text

Configure the application to protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.