STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Application Server Security Requirements Guide

V-278959

CAT II (Medium)

The application server must dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.

Rule ID

SV-278959r1137588_rule

STIG

Application Server Security Requirements Guide

Version

V4R4

CCIs

CCI-001424, CCI-000366

Discussion

If the application does not dynamically reconfigure the data security attributes as data is created and combined, there is the possibility that the security attributes will not correctly reflect the data with which they are associated. Security attributes are abstractions representing the basic properties or characteristics of an entity (e.g., subjects and objects) with respect to safeguarding information. These attributes are typically associated with internal data structures (e.g., data records, buffers, files) within the application and are used to enable the implementation of access control and flow control policies, reflect special dissemination, handling or distribution instructions, or support other aspects of the information security policy. Organizations define the security attributes of their data (e.g., classified, CUI). When data is created and/or combined, data security attributes defined by organizational policy must be dynamically created and/or updated to reflect the potential change in data sensitivity and characteristics. Dynamic association of security attributes is appropriate whenever the security characteristics of information changes over time. Security attributes may change, for example, due to information aggregation issues (i.e., the security characteristics of individual information elements are different from the combined elements), changes in individual access authorizations (i.e., privileges), and changes in the security category of information. This requirement also applies to Zero Trust initiatives.

Check Content

Verify the application server is configured to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.

If the application server does not dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined, this is a finding.

Fix Text

Configure the application server to dynamically associate security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.