Rule ID
SV-278959r1137588_rule
Version
V4R4
CCIs
CCI-001424, CCI-000366
If the application does not dynamically reconfigure the data security attributes as data is created and combined, there is the possibility that the security attributes will not correctly reflect the data with which they are associated. Security attributes are abstractions representing the basic properties or characteristics of an entity (e.g., subjects and objects) with respect to safeguarding information. These attributes are typically associated with internal data structures (e.g., data records, buffers, files) within the application and are used to enable the implementation of access control and flow control policies, reflect special dissemination, handling or distribution instructions, or support other aspects of the information security policy. Organizations define the security attributes of their data (e.g., classified, CUI). When data is created and/or combined, data security attributes defined by organizational policy must be dynamically created and/or updated to reflect the potential change in data sensitivity and characteristics. Dynamic association of security attributes is appropriate whenever the security characteristics of information changes over time. Security attributes may change, for example, due to information aggregation issues (i.e., the security characteristics of individual information elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), and changes in the security category of information. This requirement also applies to Zero Trust initiatives.
Verify the application server is configured to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined. If the application server does not dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined, this is a finding.
Configure the application server to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.