Item Search

NameAudit NamePluginCategory
DISA_STIG_IBM_WebSphere_Liberty_Server_v2r4.audit from DISA IBM WebSphere Liberty Server STIG v2r4DISA IBM WebSphere Liberty Server STIG v2r4Unix
DISA_STIG_IBM_WebSphere_Traditional_9_v2r1_Middleware.audit from DISA IBM WebSphere Traditional V9.x v2r1 STIGDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix
DISA_STIG_IBM_WebSphere_Traditional_9_Windows_v2r1.audit from DISA IBM WebSphere Traditional V9.x v2r1 STIGDISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows
WBSP-AS-000020 - The WebSphere Application Server admin console session timeout must be configured.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000070 - The WebSphere Application Server security auditing must be enabled.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

WBSP-AS-000080 - The WebSphere Application Server groups in the user registry mapped to WebSphere auditor roles must be configured in accordance with the security plan.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000090 - The WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

WBSP-AS-000100 - The WebSphere Application Server audit event type filters must be configured.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WBSP-AS-000110 - The WebSphere Application Server audit service provider must be enabled.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000120 - The WebSphere Application Server automatic repository checkpoints must be enabled to track configuration changesDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000130 - The WebSphere Application Server administrative security must be enabled.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000150 - The WebSphere Application Server users in a local user registry group must be authorized for that group.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-000160 - The WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000170 - The WebSphere Application Server global application security must be enabledDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-000180 - The WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-000190 - The WebSphere Application Server security cookies must be set to HTTPOnly.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000211 - The WebSphere Application Server Java 2 security must be enabled.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000220 - The WebSphere Application Server users in the admin role must be authorized.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

WBSP-AS-000240 - The WebSphere Application Server users in a LDAP user registry group must be authorized for that group.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000320 - The WebSphere Application Server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WBSP-AS-000380 - The WebSphere Application Server must generate log records when successful/unsuccessful attempts to access subject privileges occur.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000580 - The WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirementsDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000590 - The WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirementsDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000630 - The WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alertsDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000650 - The WebSphere Application Server audit subsystem failure action must be set to Log warning.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000660 - The WebSphere Application Server must shut down by default upon log failure (unless availability is an overriding concern).DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000670 - The WebSphere Application Server high availability applications must be configured to fail over to another system in the event of log subsystem failure.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000750 - The WebSphere Application Server must protect log information from unauthorized modification.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000780 - The WebSphere Application Server wsadmin file must be protected from unauthorized modification.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000790 - The WebSphere Application Server wsadmin file must be protected from unauthorized deletion.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000910 - The WebSphere Application Server process must not be started from the command line with the -password option.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBSP-AS-000920 - The WebSphere Application Server files must be owned by the non-root WebSphere user ID.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBSP-AS-000930 - The WebSphere Application Server sample applications must be removed.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBSP-AS-000980 - The WebSphere Application Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBSP-AS-001080 - The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001090 - The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001110 - The WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001120 - The WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001200 - The WebSphere Application Server secure LDAP (LDAPS) must be used for authentication.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001210 - The WebSphere Application Server must prohibit the use of cached authenticators after an organization-defined time period.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001290 - The WebSphere Application Server must utilize FIPS 140-2-approved encryption modules when authenticating users and processes.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001300 - The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001530 - The WebSphere Application Server must periodically regenerate LTPA keys.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001570 - The WebSphere Application Server high availability applications must be installed on a cluster.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001580 - The WebSphere Application Server memory session settings must be defined according to application load requirements.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001590 - The WebSphere Application Server thread pool size must be defined according to application load requirementsDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001610 - The WebSphere Application Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001630 - The WebSphere Application Server plugin must be configured to use HTTPS onlyDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001750 - The WebSphere Application Server must apply the latest security fixes.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

WBSP-AS-001760 - The WebSphere Application Server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVMs, CTOs, DTMs, and STIGs).DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY