This NIST 800-53 report is posted on the Internet to promote Version 3.0 of LJK/Security . The corresponding vulnerability report for your own system should be guarded more carefully, such as by being reviewed only from local HTML disk files rather than via a web server.

Return to Main Page
Invasive Testing IA_06_1_1_9

FIPS 199 High Impact (for ICS)

Findings Color Code
Satisfied
Other Than Satisfied - not assessed
Other Than Satisfied - failed

NIST SP 800-53A IA-06 .01

Question: Was source code reviewed in testing the VMS break-in evasion, LOGINOUT, SET PASSWORD, LGI-callout and ACME Agent obscuring feedback of authentication information to protect the information from possible exploitation/use by unauthorized individuals ?

Answered by: BOSTON::HARRISON

As part of Invasive Testing group: TEST_VMS_FEEDBACK

Answer: YES

This NIST 800-53 report is posted on the Internet to promote Version 3.0 of LJK/Security . The corresponding vulnerability report for your own system should be guarded more carefully, such as by being reviewed only from local HTML disk files rather than via a web server.