Rule ID
SV-288147r1252026_rule
Version
V1R0.1
This includes verification of digital signatures protecting identity assertions and access tokens, as well as included metadata. Metadata includes information about the access request such as information unique to user, system or information resource being accessed, or the transaction itself such as time. Protected system and information resources could include connected networks, applications, and Application Programming Interfaces (APIs).
Review the application documentation and deployed configuration to determine whether the application protects the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed. If the application does not protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed, this is a finding.
Configure the application to protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.