CIS Apache HTTP Server 2.4 L2 v2.1.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Apache HTTP Server 2.4 L2 v2.1.0

Updated: 2/10/2025

Authority: CIS

Plugin: Unix

Revision: 1.3

Estimated Item Count: 39

File Details

Filename: CIS_Apache_HTTP_Server_2.4_Benchmark_v2.1.0_Level_2.audit

Size: 138 kB

MD5: 0d49092df39dc519602ef20c7400c443
SHA256: 9e9cabba3d2975e72a27cda552b2d7acaf08ca7f4a25175e5c8e3ae795bc3e6e

Audit Changelog

 
Revision 1.3

Feb 10, 2025

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.2

Aug 28, 2024

Informational Update
  • 5.13 Ensure Access to Inappropriate File Extensions Is Restricted - 'httpd.conf FileMatch directive'
  • 5.13 Ensure Access to Inappropriate File Extensions Is Restricted - 'httpd.conf approved extention FileMatch directive exists'
  • 5.16 Ensure Browser Framing Is Restricted
  • 5.17 Ensure HTTP Header Referrer-Policy is set appropriately
  • 5.18 Ensure HTTP Header Permissions-Policy is set appropriately
  • 6.2 Ensure a Syslog Facility Is Configured for Error Logging - 'Main'
  • 6.2 Ensure a Syslog Facility Is Configured for Error Logging - 'VirtualHost'
  • 7.10 Ensure OCSP Stapling Is Enabled - SSLStaplingCache
  • 7.10 Ensure OCSP Stapling Is Enabled - SSLUseStapling
  • 7.11 Ensure HTTP Strict Transport Security Is Enabled
  • 8.3 Ensure All Default Apache Content Is Removed - 'httpd.conf Alias /icons/ /var/www/icons/ does not exist'
  • 8.3 Ensure All Default Apache Content Is Removed - 'httpd.conf Include conf/extra/httpd-autoindex.conf does not exists'
Miscellaneous
  • References updated.
Revision 1.1

Jun 17, 2024

Miscellaneous
  • Metadata updated.