Skip to content

The service account used to run the web service must have its password changed at least annually.

An XCCDF Rule

Description

<VulnDiscussion>Normally, a service account is established for the web service to run under rather than permitting it to run as part of the local system. The password on such accounts must be changed at least annually. If the password is not changed periodically, the potential for a malicious party to gain access to the web services account is greatly enhanced.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>Web Administrator</Responsibility><IAControls></IAControls>

ID
SV-36489r4_rule
Severity
Medium
Updated



Remediation - Manual Procedure

Ensure that the service account IDs used to run the web server and sites are documented and have their passwords changed at least annually.