This NIST 800-53 report is posted on the Internet to promote Version 3.0 of LJK/Security . The corresponding vulnerability report for your own system should be guarded more carefully, such as by being reviewed only from local HTML disk files rather than via a web server.

Return to Main Page
Invasive Testing CM_03_1_1_92

FIPS 199 High Impact (for ICS)

Findings Color Code
Satisfied
Other Than Satisfied - not assessed
Other Than Satisfied - failed

NIST SP 800-53A CM-03(01) .01(v)

Question: Did that review of source code for the add-on mechanism to document completed configuration changes to the information system modules implemented in the C or C++ programming language show the implementation avoids all dependence on null-terminated strings and instead uses counted strings ?

Answered by: BOSTON::ROOSEVELT

As part of Invasive Testing group: TEST_ADD_PROPOSE

Answer: YES

This NIST 800-53 report is posted on the Internet to promote Version 3.0 of LJK/Security . The corresponding vulnerability report for your own system should be guarded more carefully, such as by being reviewed only from local HTML disk files rather than via a web server.