Skip to content

Public web server resources must not be shared with private assets

An XCCDF Rule

Description

It is important to segregate public web server resources from private resources located behind the DoD DMZ in order to protect private assets.

Rationale

When folders, drives, or other resources are directly shared between the public web server and private servers the intent of data and resource segregation can be compromised. In addition to the requirements of the DoD Internet-NIPRNet DMZ STIG that isolates inbound traffic from external network to the internal network, resources such as printers, files, and folders/directories will not be shared between public web servers and assets located within the internal network.

ID
xccdf_org.ssgproject.content_rule_httpd_public_resources_not_shared
Severity
Medium
References
Updated