Item Search

NameAudit NamePluginCategory
AS24-W1-000160 - The Apache web server must use a logging mechanism that is configured to alert the (ISSO) and System Administrator (SA) in the event of a processing failure.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000200 - The log information from the Apache web server must be protected from unauthorized deletion and modification.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000240 - The Apache web server must not perform user management for hosted applications.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operationDISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000370 - The Apache web server must encrypt passwords during transmission.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshakeDISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000690 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000970 - The Apache web server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W2-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

ACCESS CONTROL

AS24-W2-000780 - The Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie dataDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA020 A22 - The Timeout directive must be properly set.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA028 A22 - The httpd.conf MinSpareServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - confDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - test-cgiDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA056 A22 - The MultiViews directive must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA058 W22 - Directory indexing must be disabled on directories not containing index files.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA064 W22 - The HTTP request header field size must be limited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA120 W22 - Administrative users and groups that have access rights to the web server must be documented.DISA STIG Apache Server 2.2 Windows v1r13Windows
WA140 A22 - Web server content and configuration files must be part of a routine backup program.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA140 W22 - Web server content and configuration files must be part of a routine backup program.DISA STIG Apache Server 2.2 Windows v1r13Windows
WA00510 W22 - Web server status module must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

ACCESS CONTROL

WA00520 W22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00525 A22 - User specific directories must not be globally enabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00525 A22 - User specific directories must not be globally enabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - OrderDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - OrderDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00540 W22 - The web server must be configured to explicitly deny access to the OS root.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - 80DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - '[::ffff:0.0.0.0]:80'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - 'Listen 80 does not exists'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - 'Listen directive exists'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00560 A22 - The URL-path name must be set to the file path name or the directory path name.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00560 W22 - The URL-path name must be set to the file path name or the directory path name.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00565 A22 - HTTP request methods must be limited - LimitExceptDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00565 A22 - HTTP request methods must be limited - OrderDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG040 W22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Windows v1r13Windows
WG204 A22 - A web server must be segregated from other services.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG280 - The access control files are owned by a privileged web server account - APP_Config_filesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG280 - The access control files are owned by a privileged web server account - HTACCESS_DIRDISA STIG Apache Server 2.2 Unix v1r11Unix
WG300 A22 - Web server system files must conform to minimum file permission requirements - htdocs/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG345 A22 - The web server must remove all export ciphers from the cipher suite.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WG370 A22 - MIME types for csh or sh shell programs must be disabled - ActionDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG420 A22 - Backup interactive scripts on the production web server are prohibited.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG520 A22 - Web server and/or operating system information must be protected.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION