DISA Apache Server 2.4 Windows Site STIG v2r3

Audit Details

Name: DISA Apache Server 2.4 Windows Site STIG v2r3

Updated: 6/9/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.0

Estimated Item Count: 17

File Details

Filename: DISA_STIG_Apache_Site-2.4_Windows_v2r3.audit

Size: 38.6 kB

MD5: 15ad23131546e074513b2db055934760
SHA256: 1876323626cbd534f1dc899d7d3d9a5ed52b5e9f5c4d56f82d7ca5aeaa79d44d

Audit Items

DescriptionCategories
AS24-W2-000240 - The Apache web server must not perform user management for hosted applications.

CONFIGURATION MANAGEMENT

AS24-W2-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.

CONFIGURATION MANAGEMENT

AS24-W2-000350 - Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.

CONFIGURATION MANAGEMENT

AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.

IDENTIFICATION AND AUTHENTICATION

AS24-W2-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000440 - Anonymous user access to the Apache web server application directories must be prohibited.

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application - Header HttpOnly Secure

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000540 - The Apache web server must augment re-creation to a stable and known baseline.

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000580 - The Apache web server document directory must be in a separate partition from the Apache web servers system files.

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.

SYSTEM AND INFORMATION INTEGRITY

AS24-W2-000670 - The Apache web server must restrict inbound connections from nonsecure zones.

ACCESS CONTROL

AS24-W2-000690 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.

ACCESS CONTROL

AS24-W2-000780 - The Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.

CONFIGURATION MANAGEMENT

AS24-W2-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie data

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000880 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies

SYSTEM AND COMMUNICATIONS PROTECTION

DISA_STIG_Apache_Site-2.4_Windows_v2r3.audit from DISA Apache Server 2.4 Windows Site v2r3 STIG