Item Search

NameAudit NamePluginCategory
AS24-U1-000020 - The Apache web server must perform server-side session management.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

ACCESS CONTROL

AS24-U1-000030 - The Apache web server must use cryptography to protect the integrity of remote sessionsDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000180 - The Apache web server log files must only be accessible by privileged users.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000190 - The log information from the Apache web server must be protected from unauthorized modification or deletion.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000240 - The Apache web server must not perform user management for hosted applications.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000330 - The Apache web server must have Web Distributed Authoring (WebDAV) disabled.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

CONFIGURATION MANAGEMENT

AS24-U1-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted applicationDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000550 - The Apache web server must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000650 - The Apache web server must set an inactive timeout for sessions - reqtimeout_moduleDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

ACCESS CONTROL

AS24-U1-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

ACCESS CONTROL

AS24-U1-000710 - The Apache web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the Apache web server.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000710 - The Apache web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the Apache web server.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000750 - The Apache web server must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) which are stamped at a minimum granularity of one second.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie dataDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie data.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000900 - The Apache web server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000950 - The Apache web server must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

CONFIGURATION MANAGEMENT

WA000-WWA020 W22 - The Timeout directive must be properly set.DISA STIG Apache Server 2.2 Windows v1r13Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA022 W22 - The KeepAlive directive must be enabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA050 W22 - All interactive programs must be placed in a designated directory with appropriate permissions. - 'SetHandler'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA052 A22 - The '-FollowSymLinks' setting must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA000-WWA054 W22 - Server side includes (SSIs) must run with execution capability disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA056 A22 - The MultiViews directive must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA000-WWA062 W22 - The HTTP request header fields must be limited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA066 W22 - The HTTP request line must be limited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA230 W22 - The site software used with the web server must have all applicable security patches applied and documented.DISA STIG Apache Server 2.2 Windows v1r13Windows
WA00505 A22 - Web Distributed Authoring and Versioning (WebDAV) must be disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA00505 W22 - Web Distributed Authoring and Versioning (WebDAV) must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00520 A22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00525 W22 - User specific directories must not be globally enabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00535 A22 - The score board file must be properly secured.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00547 W22 - The ability to override the access configuration for the OS root directory must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00550 W22 - The TRACE method must be disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - 0.0.0.0:80DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00565 W22 - HTTP request methods must be limited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG050 W22 - The web server service password(s) must be entrusted to the SA or Web Manager.DISA STIG Apache Server 2.2 Windows v1r13Windows
WG080 A22 - Installation of a compiler on production web server is prohibited.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG130 A22 - All utility programs, not necessary for operations, must be removed or disabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG145 W22 - The private web server must use an approved DoD certificate validation process. - 'SSLCARevocationFile'DISA STIG Apache Server 2.2 Windows v1r13Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG145 W22 - The private web server must use an approved DoD certificate validation process. - 'SSLCARevocationPath'DISA STIG Apache Server 2.2 Windows v1r13Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG200 W22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities. - 'System32\cmd.exe'DISA STIG Apache Server 2.2 Windows v1r13Windows
WG280 - The access control files are owned by a privileged web server account - .htaccess existDISA STIG Apache Server 2.2 Windows v1r13Windows
WG300 A22 - Web server system files must conform to minimum file permission requirements - cgi_binDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG345 A22 - The web server must remove all export ciphers from the cipher suite.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WG385 A22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'test-cgi'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT