DISA STIGS Viewer

The application must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application.

Overview

Finding ID Version Rule ID IA Controls Severity
V-222434 APSC-DV-000550 SV-222434r960843_rule   Low
Description
STIG Date
Application Security and Development Security Technical Implementation Guide 2025-02-12

Details

Check Text (C-24104r493210_chk)
If the application has no interactive user interface, this requirement is not applicable.

Log on to the application as a user.

Observe the screen and ensure the DoD-approved banner is displayed prior to obtaining access to the application. Refer to the vulnerability discussion for the approved text.

If the only way to access the application is through the OS console, e.g., a fat client application installed on a GFE desktop or laptop, and that GFE is configured to display the DoD banner, an additional banner is not required at the application level.

If the standard DoD-approved banner is not displayed prior to obtaining access, this is a finding.
Fix Text (F-24093r493211_fix)
Configure the application to present the standard DoD-approved banner prior to granting access to the application.