The Apache web server must augment re-creation to a stable and known baseline.
An XCCDF Rule
Description
Making certain that the web server has not been updated by an unauthorized user is always a concern. Adding patches, functions, and modules that are untested and not part of the baseline opens the possibility for security risks. The web server must offer, and not hinder, a method that allows for the quick and easy reinstallation of a verified and patched baseline to guarantee the production web server is up-to-date and has not been modified to add functionality or expose security risks. When the web server does not offer a method to roll back to a clean baseline, external methods, such as a baseline snapshot or virtualizing the web server, can be used.
- ID
- SV-214289r961122_rule
- Version
- AS24-U2-000540
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Prepare documentation for disaster recovery methods for the Apache web server in the event of the necessity for rollback.
Document and test the disaster recovery methods designed.