docs: resolve the Application Server SRG and rule it not applicable - #39
Merged
Merged
Conversation
The requirement-source register carried two DISA cross-references it could not resolve, and an open question about whether one of them applied at all. Both are now closed on evidence rather than assumption. The Application Server SRG resolves to V4R5 and is pinned by digest, then assessed as not applicable: of its 137 rules, 27 presuppose a management interface or hosted applications and 18 refer to accounts. This image has none of those, so the rules govern objects that do not exist here, and the remainder are what the Web Server SRG states for a component of this kind. It is pinned rather than dropped so the determination stays tied to the revision it was made against. The Container Platform SRG is not a scope question. V2R1 is officially released and its filename follows DISA's convention, but it is no longer served from the public download path, and the download index is now a JavaScript-rendered portal with no links in its HTML. It stays unresolved with the release, filename, and finding recorded so the search is not repeated. It blocks no part of the spine. A structural check now requires a source ruled not applicable to record the basis, on the same principle that an unpinned source must record why it is unpinned.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the two open items on the requirement-source register, on evidence rather than assumption.
Application Server SRG — resolved, then ruled not applicable
It resolves to V4R5 (benchmark date 01 Jul 2026) and is pinned by SHA-256. The digest was verified reproducible by fetching the recorded URL twice.
Having retrieved it, the applicability question the register left open is answerable from its contents. Of its 137 rules:
This image has no management interface, no accounts, and hosts no application, so those rules govern objects that do not exist here. The remainder — logging, TLS, session handling — are what the Web Server SRG already states for a component of this kind, in terms that match what this image is.
It is recorded
"role": "not-applicable"and pinned rather than dropped, so the determination stays tied to the revision it was made against. If DISA broadens the SRG's scope later, that becomes visible instead of silent.Reasoning and counts are in ADR-0010.
Container Platform SRG — stays unresolved, with the finding recorded
Not a scope question. V2R1 is officially released (24 July 2024) and the filename follows DISA's convention,
U_Container_Platform_V2R1_SRG.zip— it is simply no longer served from the public download path. That URL returns 404 whileU_Web_Server_V3R3_SRG.zipreturns 200 from the same directory, so the path and method are sound and the file is genuinely not there.The download index cannot be used to locate it either: it is now a JavaScript-rendered portal whose HTML contains no download links at all. Retrieval needs a browser session or the SRG-STIG library compilation.
It stays
unresolvedwith the release, filename, and this finding recorded, so whoever retrieves it is not repeating the search. It is a missing cross-reference, not a missing part of the spine, and it blocks nothing.Enforcement
A new structural check requires a source ruled
not-applicableto record the basis — the same principle that already makes an unpinned source record why it is unpinned. A determination without a stated reason is indistinguishable from an omission.Verified by injecting a blank basis: the check fails, and passes again when restored.
Also confirmed
The pinned Web Server SRG V3R3 is still current — V3R4, V3R5, and V4R1 all 404.
Checks
build-trace-matrix.py --checkreports no drift