Skip to content

Web Server Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000915

    Group
  • The web server must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

    A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic keys.
    Rule Medium Severity
  • SRG-APP-000920

    Group
  • SRG-APP-000925

    Group
  • The web server must compare the internal system clocks on an organization-defined frequency with organization-defined authoritative time source.

    Synchronization of internal system clocks with an authoritative source provides uniformity of time stamps for systems with multiple system clocks and systems connected over a network.
    Rule Medium Severity
  • SRG-APP-000219

    Group
  • The web server must restrict a consistent inbound source IP for the entire management session.

    Authenticity protection provides protection against man-in-the-middle attacks/session hijacking and the insertion of false information into sessions. Application communication sessions are protect...
    Rule Medium Severity
  • SRG-APP-000219

    Group
  • The web server must restrict a consistent inbound source IP for the entire user session.

    Authenticity protection provides protection against man-in-the-middle attacks/session hijacking and the insertion of false information into sessions. Application communication sessions are protect...
    Rule Info Severity
  • SRG-APP-000439

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules