| DISA_IBM_WebSphere_Liberty_Server_STIG_v2r2.audit from DISA IBM WebSphere Liberty Server STIG v2r2 | DISA IBM WebSphere Liberty Server STIG v2r2 | Unix | |
| WBSP-AS-000010 - The WebSphere Application Server maximum in-memory session count must be set according to application requirements. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL |
| WBSP-AS-000020 - The WebSphere Application Server admin console session timeout must be configured. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | ACCESS CONTROL |
| WBSP-AS-000090 - The WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000110 - The WebSphere Application Server audit service provider must be enabled. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | ACCESS CONTROL |
| WBSP-AS-000140 - The WebSphere Application Server bus security must be enabled. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| WBSP-AS-000170 - The WebSphere Application Server global application security must be enabled | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-000212 - The WebSphere Application Server Java 2 security must not be bypassed. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL |
| WBSP-AS-000230 - The WebSphere Application Server LDAP groups must be authorized for the WebSphere role. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY |
| WBSP-AS-000310 - The WebSphere Application Server management interface must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | ACCESS CONTROL |
| WBSP-AS-000380 - The WebSphere Application Server must generate log records when successful/unsuccessful attempts to access subject privileges occur. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000640 - The WebSphere Application Server must alert the SA and ISSO, at a minimum, in the event of a log processing failure | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000650 - The WebSphere Application Server audit subsystem failure action must be set to Log warning. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000670 - The WebSphere Application Server high availability applications must be configured to fail over to another system in the event of log subsystem failure. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000740 - The WebSphere Application Server must be configured to protect log information from any type of unauthorized read access. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000740 - The WebSphere Application Server must be configured to protect log information from any type of unauthorized read access. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000760 - The WebSphere Application Server must protect log information from unauthorized deletion. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000770 - The WebSphere Application Server wsadmin file must be protected from unauthorized access. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000810 - The WebSphere Application Server must be configured to encrypt log information. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000820 - The WebSphere Application Server must be configured to sign log information. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | AUDIT AND ACCOUNTABILITY |
| WBSP-AS-000940 - The WebSphere Application Server must remove JREs left by web server and plug-in installers for web servers and plugins running in the DMZ. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | CONFIGURATION MANAGEMENT |
| WBSP-AS-000960 - The WebSphere Application Server must be run as a non-admin user. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | CONFIGURATION MANAGEMENT |
| WBSP-AS-000960 - The WebSphere Application Server must be run as a non-admin user. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | CONFIGURATION MANAGEMENT |
| WBSP-AS-000970 - The WebSphere Application Server must disable JSP class reloading. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | CONFIGURATION MANAGEMENT |
| WBSP-AS-001010 - The WebSphere Application Server LDAP user registry must be used. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001010 - The WebSphere Application Server LDAP user registry must be used. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001020 - The WebSphere Application Server local file-based user registry must not be used. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001030 - The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001120 - The WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001180 - The WebSphere Application Server application security must be enabled for each security domain except for publicly available applications specified in the System Security Plan. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001180 - The WebSphere Application Server application security must be enabled for each security domain except for publicly available applications specified in the System Security Plan. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001230 - The WebSphere Application Server default keystore passwords must be changed. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001230 - The WebSphere Application Server default keystore passwords must be changed. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001260 - The WebSphere Application Server must use signer for DoD-issued certificates. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION |
| WBSP-AS-001370 - The WebSphere Application Server must use DoD-approved Signer Certificates. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001390 - The WebSphere Application Servers must not be in the DMZ. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001390 - The WebSphere Application Servers must not be in the DMZ. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001410 - The WebSphere Application Server DoD root CAs must be in the trust store. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001460 - The WebSphere Application Server personal certificates in all keystores must be issued by an approved DoD CA. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001460 - The WebSphere Application Server personal certificates in all keystores must be issued by an approved DoD CA. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001470 - The WebSphere Application Server must be configured to perform complete application deployments when using A/B clusters. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001480 - The WebSphere Application servers with an RMF categorization of high must be in a high-availability (HA) cluster. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001480 - The WebSphere Application servers with an RMF categorization of high must be in a high-availability (HA) cluster. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001520 - The WebSphere Application Server must not generate LTPA keys automatically. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001580 - The WebSphere Application Server memory session settings must be defined according to application load requirements. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001590 - The WebSphere Application Server thread pool size must be defined according to application load requirements. | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001620 - The WebSphere Application Server distribution and consistency services (DCS) transport links must be encrypted. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| WBSP-AS-001740 - The WebSphere Application Server must remove organization-defined software components after updated versions have been installed. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | SYSTEM AND INFORMATION INTEGRITY |
| WBSP-AS-001760 - The WebSphere Application Server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVMs, CTOs, DTMs, and STIGs). | DISA IBM WebSphere Traditional 9 Windows STIG v2r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WBSP-AS-001770 - The WebSphere Application Server must use FIPS 140-3-approved encryption modules when authenticating users and processes. | DISA IBM WebSphere Traditional 9 STIG v2r1 Middleware | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |