The asset owner shall have policies and procedures related to using mutual authentication for access to all server applications hosted on IACS devices, including web technology-based servers.