Item Search

NameAudit NamePluginCategory
AS24-U1-000160 - The Apache web server must use a logging mechanism that is configured to alert the Information System Security Officer (ISSO) and System Administrator (SA) in the event of a processing failure.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000250 - The Apache web server must only contain services and functions necessary for operation.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000260 - The Apache web server must not be a proxy server - ProxyRequestDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000300 - The Apache web server must have resource mappings set to disable the serving of certain file types.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000440 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000520 - The Apache web server must generate a session ID using as much of the character set as possible to reduce the risk of brute force.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-U1-000750 - The Apache web server must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) which are stamped at a minimum granularity of one secondDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000820 - The Apache web server must be protected from being stopped by a non-privileged user.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000020 - The Apache web server must perform server-side session management - session_moduleDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operation - conf/extra/proxy-html.confDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operation - httpd-manual packageDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000500 - The Apache web server must generate unique session identifiers that cannot be reliably reproduced.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000550 - The Apache web server must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - mod_reqtimeoutDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000760 - The Apache web server must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) with a minimum granularity of one second - LogFormat %tDISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000830 - The Apache web server must be tuned to handle the operational requirements of the hosted application.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000930 - The Apache web server must install security-relevant software updates within the configured time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000940 - All accounts installed with the Apache web server software and tools must have passwords assigned and default passwords changed.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

WA000-WWA058 W22 - Directory indexing must be disabled on directories not containing index files.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA064 W22 - The HTTP request header field size must be limited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA120 W22 - Administrative users and groups that have access rights to the web server must be documented.DISA STIG Apache Server 2.2 Windows v1r13Windows
WA140 W22 - Web server content and configuration files must be part of a routine backup program.DISA STIG Apache Server 2.2 Windows v1r13Windows
WA00510 W22 - Web server status module must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

ACCESS CONTROL

WA00520 W22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00540 W22 - The web server must be configured to explicitly deny access to the OS root.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - '[::ffff:0.0.0.0]:80'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - 'Listen 80 does not exists'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 W22 - The web server must be configured to listen on a specific IP address and port. - 'Listen directive exists'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00560 W22 - The URL-path name must be set to the file path name or the directory path name.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00612 A22 - The sites error logs must log the correct format.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WG040 W22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Windows v1r13Windows
WG170 A22 - Each readable web document directory must contain either a default, home, index, or equivalent file.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG255 A22 - Access to the web server log files must be restricted to administrators, web administrators, and auditors.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG265 A22 - The required DoD banner page must be displayed to authenticated users accessing a DoD private website.DISA STIG Apache Site 2.2 Unix v1r11Unix

ACCESS CONTROL

WG280 - The access control files are owned by a privileged web server account - APP_Config_filesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG290 A22 - Web client access to the content directories must be restricted to read and execute - aliasDISA STIG Apache Site 2.2 Unix v1r11Unix
WG290 A22 - Web client access to the content directories must be restricted to read and execute - script aliasDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG290 A22 - Web client access to the content directories must be restricted to read and execute - script alias matchDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG300 W22 - Web server system files must conform to minimum file permission requirements. - 'logs'DISA STIG Apache Server 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WG350 A22 - A private web server will have a valid DoD server certificate.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'extra'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG420 A22 - Backup interactive scripts on the production web server are prohibited.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG470 W22 - Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator. - 'Cscript.exe'DISA STIG Apache Server 2.2 Windows v1r13Windows