Skip to content

Microsoft SharePoint 2013 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000212

    <GroupDescription></GroupDescription>
    Group
  • The SharePoint Central Administration site must not be accessible from Extranet or Internet connections.

    &lt;VulnDiscussion&gt;SharePoint must prevent the presentation of information system management-related functionality at an interface utilized by g...
    Rule Medium Severity
  • SRG-APP-000039

    <GroupDescription></GroupDescription>
    Group
  • For environments requiring an Internet-facing capability, the SharePoint application server upon which Central Administration is installed, must not be installed in the DMZ.

    &lt;VulnDiscussion&gt;Information flow control regulates where information is allowed to travel within an information system and between informatio...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The SharePoint farm service account (database access account) must be configured with minimum privileges in Active Directory (AD).

    &lt;VulnDiscussion&gt;Separation of duties is a prevalent Information Technology control implemented at different layers of the information system ...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The SharePoint farm service account (database access account) must be configured with minimum privileges on the SQL server.

    &lt;VulnDiscussion&gt;Separation of duties is a prevalent Information Technology control implemented at different layers of the information system ...
    Rule Medium Severity
  • SRG-APP-000516

    <GroupDescription></GroupDescription>
    Group
  • The SharePoint setup account must be configured with the minimum privileges in Active Directory.

    &lt;VulnDiscussion&gt;Separation of duties is a prevalent Information Technology control implemented at different layers of the information system ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules