Skip to content

Application Server Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000100

    <GroupDescription></GroupDescription>
    Group
  • The application server must generate log records containing information that establishes the identity of any individual or process associated with the event.

    &lt;VulnDiscussion&gt;Information system logging capability is critical for accurate forensic analysis. Log record content that may be necessary to...
    Rule Medium Severity
  • SRG-APP-000101

    <GroupDescription></GroupDescription>
    Group
  • The application server must generate log records containing the full-text recording of privileged commands or the individual identities of group account users.

    &lt;VulnDiscussion&gt;Privileged commands are commands that change the configuration or data of the application server. Since this type of command...
    Rule Medium Severity
  • SRG-APP-000108

    <GroupDescription></GroupDescription>
    Group
  • The application server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.

    &lt;VulnDiscussion&gt;Logs are essential to monitor the health of the system, investigate changes that occurred to the system, or investigate a sec...
    Rule Medium Severity
  • SRG-APP-000109

    <GroupDescription></GroupDescription>
    Group
  • The application server must shut down by default upon log failure (unless availability is an overriding concern).

    &lt;VulnDiscussion&gt;It is critical that, when a system is at risk of failing to process logs, it detects and takes action to mitigate the failure...
    Rule Medium Severity
  • SRG-APP-000109

    <GroupDescription></GroupDescription>
    Group
  • The application server must be configured to fail over to another system in the event of log subsystem failure.

    &lt;VulnDiscussion&gt;This requirement is dependent upon system MAC and availability. If the system MAC and availability do not specify redundancy...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules