STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 10 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

General Application (GAPP) Security Requirements Guide

Archived

Version

V1R0.1

Release Date

Jul 29, 2026

SCAP Benchmark ID

General_Application_SRG

Total Checks

163

Tags

application
CAT I: 15CAT II: 148CAT III: 0

This Security Requirements Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (163)

V-288135HIGHThe application must use an approved DoW Enterprise Identity, Credential, and Access Management (E-ICAM) solution to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).V-288136HIGHThe application must use multifactor authentication (MFA).V-288137HIGHLocal accounts must be removed after multifactor authentication (MFA) is configured. It is permissible for an emergency ("break glass") or service account to remain if absolutely required by the application. In this case, the associated complexity requirements apply.V-288138MEDIUMThe application must use a SHA 2-384 or higher hash function to provide replay-resistant authentication mechanisms for network access to all accounts.V-288139MEDIUMThe application must disable identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.V-288140MEDIUMWhen using Public Key Infrastructure (PKI)-based authentication for user access, the application must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.V-288141MEDIUMThe application, when using PKI-based authentication, must enforce authorized access to the corresponding private key.V-288142MEDIUMThe application must map the authenticated identity to the individual user or group account for Public Key Infrastructure (PKI)-based authentication.V-288143MEDIUMThe application must prohibit the use of cached authenticators after 12 hours.V-288144MEDIUMThe application must only allow the use of DoW-approved (or other authorizing official [AO]-approved) Public Key Infrastructure (PKI)-established certificate authorities (CAs) for verification of the establishment of protected sessions.V-288145MEDIUMThe application must employ identity providers and authorization servers to manage user, device, and nonperson entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with organization-defined identification and authentication policy using organization-defined mechanisms.V-288146MEDIUMThe application must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.V-288147MEDIUMThe application must protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.V-288148MEDIUMThe application must generate assertions in accordance with organization-defined identification and authentication policy.V-288149MEDIUMThe application must issue assertions in accordance with organization-defined identification and authentication policy.V-288150MEDIUMThe application must refresh assertions in accordance with organization-defined identification and authentication policy.V-288151MEDIUMThe application must revoke assertions in accordance with organization-defined identification and authentication policy.V-288152MEDIUMThe application must time-restrict assertions in accordance with organization-defined identification and authentication policy.V-288153MEDIUMThe application must audience-restrict assertions in accordance with organization-defined identification and authentication policy.V-288154MEDIUMThe application must generate access tokens in accordance with organization-defined identification and authentication policy.V-288155MEDIUMThe application must issue access tokens in accordance with organization-defined identification and authentication policy.V-288156MEDIUMThe application must refresh access tokens in accordance with organization-defined identification and authentication policy.V-288157MEDIUMThe application must revoke access tokens in accordance with organization-defined identification and authentication policy.V-288158MEDIUMThe application must time-restrict access tokens in accordance with organization-defined identification and authentication policy.V-288159MEDIUMThe application must audience-restrict access tokens in accordance with organization-defined identification and authentication policy.V-288160MEDIUMThe application must automatically remove or disable temporary user accounts after 72 hours.V-288161MEDIUMThe application must automatically disable accounts after a 35-day period of account inactivity.V-288162MEDIUMThe application must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.V-288163MEDIUMThe application must enforce a minimum 15-character password length.V-288164MEDIUMThe application must enforce password complexity by requiring that at least one uppercase character be used.V-288165MEDIUMThe application must enforce password complexity by requiring that at least one lowercase character be used.V-288166MEDIUMThe application must enforce password complexity by requiring that at least one numeric character be used.V-288167MEDIUMThe application must enforce password complexity by requiring that at least one special character be used.V-288168MEDIUMThe application must require the change of at least 50 percent of the characters when passwords are changed.V-288169MEDIUMThe application must enforce 24 hours/one day as the minimum password lifetime.V-288170MEDIUMThe application must enforce a 60-day maximum password lifetime restriction.V-288171MEDIUMThe application must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.V-288172MEDIUMThe application must automatically disable temporary and emergency accounts after 72 hours.V-288173MEDIUMThe application must terminate shared/group account credentials when members leave the group.V-288174MEDIUMThe application must automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded.V-288175MEDIUMThe application must disable accounts when the accounts have expired.V-288176MEDIUMThe application must disable accounts when the accounts are no longer associated to a user.V-288177MEDIUMThe application must disable accounts when the accounts are in violation of organizational policy.V-288178MEDIUMFor accounts using password authentication, the application must use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of the password authentication process.V-288179MEDIUMFor accounts using password authentication, the application must store only cryptographic representations of passwords.V-288180MEDIUMThe application must, for password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.V-288181MEDIUMThe application must, for password-based authentication, update the list of known passwords on an organization-defined frequency.V-288182MEDIUMThe application must, for password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.V-288183MEDIUMThe application must, for password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).V-288184MEDIUMThe application must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.V-288185MEDIUMThe application must, for password-based authentication, require immediate selection of a new password upon account recovery.V-288186MEDIUMThe application must, for password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.V-288187MEDIUMThe application must, for password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.V-288188MEDIUMThe application must, for password-based authentication, enforce organization-defined composition and complexity rules.V-288189MEDIUMThe application must limit the number of concurrent sessions to a maximum number of three for all accounts and/or account types.V-288190MEDIUMThe application must terminate all network connections associated with a communications session at the end of the session, or no more than 15 minutes of inactivity.V-288191MEDIUMThe application must invalidate session identifiers upon user logout or other session termination.V-288192MEDIUMApplications must recognize only system-generated session identifiers (IDs).V-288193MEDIUMThe application must generate unique session identifiers using a FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm.V-288194MEDIUMApplications requiring user access authentication must provide a logout function for user-initiated communication sessions.V-288195MEDIUMThe application must display an explicit logout message to users indicating the reliable termination of authenticated communications sessions.V-288196MEDIUMThe application must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.V-288197MEDIUMThe application must automatically audit account creation.V-288198MEDIUMThe application must automatically audit account modifications to include disabling/removal actions and attempts to access privileges.V-288199MEDIUMThe application must reveal error messages only to the information system security officer (ISSO), information system security manager (ISSM), if assigned, and/or security personnel as appropriate.V-288200MEDIUMIn the event of an audit processing failure, the application must alert the information system security officer (ISSO), information system security manager (ISSM) at a minimum (if assigned) and/or security personnel as appropriate.V-288201MEDIUMThe application must generate error messages that only provide the information necessary for corrective actions without revealing information that could be exploited.V-288202MEDIUMThe application must notify system administrators (SAs) and the information system security officer (ISSO) when accounts are created.V-288203MEDIUMThe application must notify system administrators (SAs) and the information system security officer (ISSO) when accounts are modified to include disabling and removal actions.V-288204MEDIUMThe application must allow only the information system security manager (ISSM), or individuals or roles appointed by the ISSM, to select which auditable events are to be audited.V-288205MEDIUMThe application must initiate session auditing upon startup.V-288206MEDIUMThe application must produce audit records containing descriptions of the audit events.V-288207MEDIUMThe application must produce audit records containing information to establish when (date and time) the events occurred.V-288208MEDIUMThe application must produce audit records containing information to establish source and destination addresses.V-288209MEDIUMThe application must produce audit records that contain information to establish success indicators, fail indicators, and enforcement actions.V-288210MEDIUMThe application must generate audit records containing information that establishes the identity of any individual or process associated with the event.V-288211MEDIUMThe application must protect audit information from any type of unauthorized read access.V-288212MEDIUMThe application must protect audit information from unauthorized modification.V-288213MEDIUMThe application must protect audit information from unauthorized deletion.V-288214MEDIUMThe application must protect audit tools from unauthorized access.V-288215MEDIUMThe application must automatically audit account enabling actions.V-288216MEDIUMThe application must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.V-288217MEDIUMThe application must generate audit records when successful/unsuccessful attempts to access security objects occur.V-288218MEDIUMThe application must generate audit records when successful/unsuccessful attempts to access security levels occur.V-288219MEDIUMThe application must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.V-288220MEDIUMThe application must generate audit records when successful/unsuccessful attempts to modify privileges occur.V-288221MEDIUMThe application must generate audit records when successful/unsuccessful attempts to modify security objects occur.V-288222MEDIUMThe application must generate audit records when successful/unsuccessful attempts to modify security levels occur.V-288223MEDIUMThe application must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.V-288224MEDIUMThe application must generate audit records when successful/unsuccessful attempts to delete privileges occur.V-288225MEDIUMThe application must generate audit records when successful/unsuccessful attempts to delete security levels occur.V-288226MEDIUMThe application must generate audit records when successful/unsuccessful attempts to delete security objects occur.V-288227MEDIUMThe application must generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur.V-288228MEDIUMThe application must generate audit records when successful/unsuccessful logon attempts occur.V-288229MEDIUMThe application must generate audit records for privileged activities or other system-level access.V-288230MEDIUMThe application must generate audit records showing starting and ending time for user access to the system.V-288231MEDIUMThe application must generate audit records when concurrent logons from different workstations occur.V-288232MEDIUMThe application must generate audit records when successful/unsuccessful accesses to objects occur.V-288233MEDIUMThe application must generate audit records for all direct access to the information system.V-288234MEDIUMThe application must generate audit records for all account creations, modifications, disabling, and termination events.V-288235MEDIUMThe application must generate audit records for all load, unload, and restart events, and also for all program initiations.V-288236MEDIUMWhen baseline configurations are changed in an unauthorized manner the application must alert the information system security officer (ISSO)/information system security manager (ISSM), and rollback the unauthorized change.V-288237MEDIUMApplications performing maintenance functions must restrict use of these functions to authorized personnel only.V-288238MEDIUMApplications used for nonlocal maintenance sessions must audit organization-defined audit events for nonlocal maintenance and diagnostic sessions.V-288239MEDIUMApplications used for nonlocal maintenance sessions must protect nonlocal maintenance sessions by separating the maintenance session from other network sessions by either physically separated communications paths or logically separated communications paths based upon encryption.V-288240MEDIUMApplications used for nonlocal maintenance sessions must use FIPS-validated keyed-hash message authentication code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.V-288241MEDIUMApplications used for nonlocal maintenance sessions must verify remote disconnection at the termination of nonlocal maintenance and diagnostic sessions.V-288242MEDIUMThe application must retain the Standard Mandatory DoW Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.V-288243MEDIUMThe publicly accessible application must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the application.V-288244HIGHThe application must off-load audit records onto a central logging system at least every seven days.V-288245HIGHThe application must use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to generate cryptographic hashes.V-288246HIGHThe application must use Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) cryptographic algorithms.V-288247HIGHThe application must use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification.V-288248HIGHThe application must use a FIPS-validated cryptographic module to provision digital signatures.V-288249HIGHThe application must implement cryptographic mechanisms to prevent unauthorized modification of information at rest.V-288250MEDIUMThe application must use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions.V-288251MEDIUMThe application must monitor remote access methods.V-288252MEDIUMThe application must control remote access methods.V-288253HIGHThe application must use TLS 1.2 or greater to protect the confidentiality and integrity of all remote access sessions.V-288254HIGHThe application must use FIPS-validated cryptographic algorithms defined in Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) to protect the confidentiality and integrity of transmitted information.V-288255HIGHThe application must use FIPS-validated cryptographic algorithms defined in CNSA 2.0 to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications.V-288256HIGHThe application must prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0.V-288257MEDIUMThe application must use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B for authentication to a cryptographic module.V-288258MEDIUMThe application must validate certificates used for Transport Layer Security (TLS) functions by performing RFC 5280-compliant certification path validation.V-288259MEDIUMThe application, for PKI-based authentication, must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.V-288260MEDIUMThe application must, for public key-based authentication, implement a local cache of revocation data to support path discovery and validation.V-288261MEDIUMThe application must include only approved trust anchors in trust stores or certificate stores managed by the organization.V-288262MEDIUMThe application must enforce a role-based access control (RBAC) policy over defined subjects and objects.V-288263MEDIUMThe application must separate user functionality (including user interface services) from information system management functionality.V-288264MEDIUMThe application must dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.V-288265MEDIUMThe application must enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.V-288266MEDIUMThe application must enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.V-288267MEDIUMThe application must associate organization-defined security attributes with information exchanged between information systems.V-288268MEDIUMThe application must dynamically associate security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined.V-288269MEDIUMThe application must uniquely identify and authenticate source points by organization, system, application, and/or individual for information transfer.V-288270MEDIUMThe application must implement organization-defined mechanisms or techniques to bind security attributes to transmitted information.V-288271MEDIUMThe application must attach data tags containing organization-defined authorized processing to organization-defined elements of personally identifiable information (PII).V-288272MEDIUMThe application must attach data tags containing organization-defined processing purposes to organization-defined elements of personally identifiable information (PII).V-288273MEDIUMThe application must enforce attribute-based access control policy over defined subjects and objects based upon organization-defined attributes to assume access permissions.V-288274MEDIUMThe application must identify prohibited mobile code.V-288275MEDIUMThe application must prompt the user for action prior to executing mobile code.V-288276MEDIUMThe application must prevent the execution of prohibited mobile code.V-288277MEDIUMThe application must block, quarantine, and/or alert administrators when prohibited mobile code is identified.V-288278MEDIUMThe application must prevent the download of prohibited mobile code.V-288279MEDIUMThe application must prevent the automatic execution of mobile code in, at a minimum, office applications, browsers, email clients, mobile code runtime environments, and mobile agent systems.V-288280MEDIUMApplications scanning for malicious code must scan all media used for system maintenance prior to use.V-288281MEDIUMThe application must automatically update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy.V-288282MEDIUMThe application must configure malicious code protection mechanisms to perform periodic scans of the information system every seven days.V-288283MEDIUMThe application must be configured to perform real-time malicious code protection scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.V-288284MEDIUMThe application must be configured to block and quarantine malicious code upon detection.V-288285MEDIUMThe application must implement nonsignature-based malicious code detection mechanisms.V-288286MEDIUMThe application must configure malicious code protection mechanisms to send alerts to organization-defined personnel in response to malicious code detection.V-288287MEDIUMThe application that implements spam protection mechanisms must be updated automatically.V-288288MEDIUMThe application must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization.V-288289MEDIUMThe application must remove organization-defined software components after updated versions have been installed.V-288290HIGHThe application must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).V-288291MEDIUMThe application must implement cryptographic mechanisms to authenticate organization-defined software or firmware components prior to installation.V-288292MEDIUMThe application must disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.V-288293MEDIUMThe application must prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithms for transmission.V-288294MEDIUMThe application must use the system clock.V-288295HIGHThe application must be a version supported by the vendor.V-288296MEDIUMThe application must be configured to disable nonessential functions.V-288297MEDIUMThe application must be configured in accordance with the security configuration settings based on DoW security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.