Skip to content

APACHE 2.2 Site for Windows Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Anonymous FTP user access to interactive scripts must be prohibited.

    The directories containing the CGI scripts, such as PERL, must not be accessible to anonymous users via FTP. This applies to all directories that contain scripts that can dynamically produce web pa...
    Rule Medium Severity
  • WG460

    Group
  • WG205

    Group
  • WG265

    Group
  • The required DoD banner page must be displayed to authenticated users accessing a DoD private website.

    A consent banner will be in place to make prospective entrants aware that the website they are about to enter is a DoD web site and their activity is subject to monitoring. The document, DoDI 8500....
    Rule Low Severity
  • WG140

    Group
  • WG235

    Group
  • Web Administrators must only use encrypted connections for Document Root directory uploads.

    Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An enc...
    Rule High Severity
  • WG242

    Group
  • WG255

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules