DISA STIGS Viewer

Security-relevant software updates and patches must be kept up to date.

Overview

Finding ID Version Rule ID IA Controls Severity
V-222614 APSC-DV-002630 SV-222614r961683_rule   Medium
Description
STIG Date
Application Security and Development Security Technical Implementation Guide 2025-02-12

Details

Check Text (C-24284r493750_chk)
Review the application documentation to identify application versions and patching.

Interview the application administrator and inquire about patching process.

Review IAVMs and CTOs to determine if the application is being updated in accordance with authoritative sources.

If application updates are not checked on at least on a weekly basis and applied immediately or in accordance with POA&Ms, IAVMs, CTOs, DTMs or other authoritative patching guidelines or sources, this is a finding.
Fix Text (F-24273r493751_fix)
Check for application updates at least weekly and apply patches immediately or in accordance with POA&Ms, IAVMs, CTOs, DTMs or other authoritative patching guidelines or sources.