Skip to content

The web server must initiate session logging upon start up.

An XCCDF Rule

Description

An attacker can compromise a web server during the startup process. If logging is not initiated until all the web server processes are started, key information may be missed and not available during a forensic investigation. To assure all logable events are captured, the web server must begin logging once the first web server process is initiated.

ID
SV-206357r960888_rule
Version
SRG-APP-000092-WSR-000055
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the web server to capture logable events upon startup.