Skip to content

APACHE 2.2 Site for Windows Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Private web servers must require certificates issued from a DoD-authorized Certificate Authority.

    Web sites requiring authentication within the DoD must utilize PKI as an authentication mechanism for web users. Information systems residing behind web servers requiring authorization based on ind...
    Rule Medium Severity
  • Log file data must contain required data elements.

    The use of log files is a critical component of the operation of the Information Systems (IS) used within the DoD, and they can provide invaluable assistance with regard to damage assessment, causa...
    Rule Medium Severity
  • Public web servers must use TLS if authentication is required.

    Transport Layer Security (TLS) is optional for a public web server. However, if authentication is being performed, then the use of the TLS protocol is required. Without the use of TLS, the authen...
    Rule Medium Severity
  • Error logging must be enabled.

    The server error logs are invaluable because they can also be used to identify potential problems and enable proactive remediation. Log data can reveal anomalous behavior such as “not found” or “un...
    Rule Medium Severity
  • The sites error logs must log the correct format.

    The server error logs are invaluable because they can also be used to identify potential problems and enable proactive remediation. Log data can reveal anomalous behavior such as “not found” or “u...
    Rule Medium Severity
  • The web document (home) directory must be in a separate partition from the web server’s system files.

    Application partitioning enables an additional security measure by securing user traffic under one security context, while managing system and application files under another. Web content is access...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules