Hosted applications must be documented in the system security plan.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-223007
TCAT-AS-001710
SV-223007r961863_rule
Low
Description
The ISSM/ISSO must be cognizant of all applications operating on the Tomcat server, and must address any security implications associated with the operation of the applications.
If unknown/undocumented applications are operating on the Tomcat server, these applications increase risk for the system due to not being managed, patched or monitored for unapproved activity on the system.