Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
An XCCDF Rule
Description
By separating web server security functions from non-privileged users, roles can be developed that can then be used to administer the web server. Forcing users to change from a non-privileged account to a privileged account when operating on the web server or on security-relevant information forces users to only operate as a web server administrator when necessary. Operating in this manner allows for better logging of changes and better forensic information and limits accidental changes to the web server.
- ID
- SV-214389r399775_rule
- Version
- AS24-W2-000690
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Restrict access to the web administration tool to only the SA, Web Manager, or the Web Manager designees.