Item Search

NameAudit NamePluginCategory
2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 10 L2 v1.1.0 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 8 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 9 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 11 v1.0.0 L2Unix

CONFIGURATION MANAGEMENT

AS24-W1-000010 - The Apache web server must limit the number of allowed simultaneous session requests.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000010 - The Apache web server must limit the number of allowed simultaneous session requests.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000065 - System logging must be enabled.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000180 - The Apache web server log files must only be accessible by privileged users.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000200 - The log information from the Apache web server must be protected from unauthorized deletion and modification.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operation - SetHandler otherDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operation - Welcome pageDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000260 - The Apache web server must not be a proxy server.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000280 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000300 - The Apache web server must have resource mappings set to disable the serving of certain file types.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000300 - The Apache web server must have resource mappings set to disable the serving of certain file types.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and port - IP or Port OnlyDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and port - Zero IPs OnlyDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000370 - The Apache web server must encrypt passwords during transmission.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000380 - The Apache web server must only accept client DOD-approved and RFC 5280-compliant certificates.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application - Javascript setCookieDISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000530 - The Apache web server must generate unique session identifiers with definable entropy - ssl_moduleDISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000590 - The Apache web server must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - RequestReadTimeoutDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000710 - The Apache web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the Apache web server.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000730 - The Apache web server must be configurable to integrate with an organizations security infrastructure.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000730 - The Apache web server must be configurable to integrate with an organizations security infrastructure.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000760 - The Apache web server must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) with a minimum granularity of one secondDISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000800 - The Apache web server must only accept client certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs).DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000860 - The Apache web server cookies, such as session cookies, sent to the client using SSL/TLS must not be compressed.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000930 - The Apache web server must install security-relevant software updates within the configured time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000940 - All accounts installed with the Apache web server software and tools must have passwords assigned and default passwords changed.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - confDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - Options NoneDISA STIG Apache Server 2.2 Unix v1r11Unix
WA00510 A22 - Web server status module must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00510 A22 - Web server status module must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00510 W22 - Web server status module must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

ACCESS CONTROL

WA00530 A22 - The process ID (PID) file must be properly secured - configDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - apacheDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - apache/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - cgi_binDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - configDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - htdocsDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - htdocs/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - logsDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - logs/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT