STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Application Server Security Requirements Guide

V-204780

CAT II (Medium)

The application server must associate organization-defined types of security attributes having organization-defined security attribute values with information in process.

Rule ID

SV-204780r961272_rule

STIG

Application Server Security Requirements Guide

Version

V4R4

CCIs

CCI-002263

Discussion

The application server provides a framework for applications to communicate between each other to form an overall well-designed application to perform a task. As the information traverses the application server and the components, the security attributes must be maintained. Without the association of security attributes to information, there is no basis for the application server or hosted applications to make security-related access control decisions. The security attributes are abstractions representing the basic properties or characteristics of an entity (e.g., subjects and objects) with respect to safeguarding information. One example includes marking data as classified or FOUO. These security attributes may be assigned manually or during data processing, but either way, it is imperative these assignments are maintained while the data is in process. If the security attributes are lost when the data is being processed, there is the risk of a data compromise.

Check Content

Review the application server documentation to determine if the application associates organization-defined types of security attributes with organization-defined security attribute values to information in process.

If the application server does not associate the security attributes to information in process or the feature is not implemented, this is a finding.

Fix Text

Configure the application server to associate organization-defined types of security attributes having organization-defined security attribute values with information in process.