The web server must initiate session logging upon start up.
An XCCDF Rule
Description
An attacker can compromise a web server during the startup process. If logging is not initiated until all the web server processes are started, key information may be missed and not available during a forensic investigation. To assure all logable events are captured, the web server must begin logging once the first web server process is initiated.
- ID
- SV-206357r960888_rule
- Version
- SRG-APP-000092-WSR-000055
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the web server to capture logable events upon startup.