Item Search

NameAudit NamePluginCategory
2.3.7 (L1) Ensure 'Control use of insecure content exceptions' is set to 'Enabled: Do not allow any site to load mixed content'CIS Google Chrome Group Policy v1.1.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

6.6 Remove sample databases if installedCIS Sybase 15.0 L1 DB v1.1.0SybaseDB
AS24-U2-000030 - The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000360 - The Apache web server must be configured to use a specified IP address and port.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000810 - The Apache web server must only accept client certificates issued by DOD PKI or DoD-approved PKI Certification Authorities (CAs) - CAs.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000960 - The Apache web server must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-W1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application - Header HttpOnly secureDISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000530 - The Apache web server must generate unique session identifiers with definable entropy.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000580 - The Apache web server document directory must be in a separate partition from the Apache web servers system files.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W2-000240 - The Apache web server must not perform user management for hosted applications.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application - Header HttpOnly SecureDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000003 - OHS must have the MaxClients directive defined to limit the number of allowed simultaneous requests.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

UBTU-18-010005 - The Ubuntu operating system must implement NIST FIPS-validated cryptography to protect classified information and for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA STIG Ubuntu 18.04 LTS v2r15Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA020 A22 - The Timeout directive must be properly set.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA022 A22 - The KeepAlive directive must be enabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA024 A22 - The KeepAliveTimeout directive must be defined.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA032 A22 - The httpd.conf MaxClients directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - printenvDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - printenvDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA120 A22 - Administrative users and groups that have access rights to the web server must be documented.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA230 A22 - The Web site software used with the web server must have all applicable security patches applied and documented.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND INFORMATION INTEGRITY

WA00535 A22 - The score board file must be properly secured.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA00615 W22 - System logging must be enabled. - 'CustomLog'DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WA00615 W22 - System logging must be enabled. - 'ErrorLog'DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WG080 A22 - Installation of a compiler on production web server is prohibited.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG145 A22 - The private web server must use an approved DoD certificate validation process.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG204 A22 - A web server must be segregated from other services.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG220 A22 - Web administration tools must be restricted to the web manager and the web manager's designees - ResourceConfigDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG235 W22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Windows v1r13Windows
WG240 W22 - Logs of web server access and errors must be established and maintained.DISA STIG Apache Site 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG250 W22 - Log file access must be restricted to System Administrators, Web Administrators or Auditors.DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WG265 W22 - The required DoD banner page must be displayed to authenticated users accessing a DoD private website.DISA STIG Apache Site 2.2 Windows v1r13Windows

ACCESS CONTROL

WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'ScriptAliasMatch'DISA STIG Apache Site 2.2 Windows v1r13Windows
WG300 A22 - Web server system files must conform to minimum file permission requirements - logsDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - logs/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - confDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - findDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG370 A22 - MIME types for csh or sh shell programs must be disabled - AddHandlerDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG400 A22 - All interactive programs (CGI) must be placed in a designated directory with appropriate permissions.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG400 W22 - All interactive programs must be placed in a designated directory with appropriate permissions.DISA STIG Apache Site 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG440 A22 - Monitoring software must include CGI or equivalent programs in its scope.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG490 W22 - Java software on production web servers must be limited to class files and the JAVA virtual machine. - 'Alias - *.jpp'DISA STIG Apache Site 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG490 W22 - Java software on production web servers must be limited to class files and the JAVA virtual machine. - 'ScriptAlias_Match - *.jpp'DISA STIG Apache Site 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT