Skip to content

Web Administrators must only use encrypted connections for Document Root directory uploads.

An XCCDF Rule

Description

Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An encrypted protocol or service must be used for remote access to web administration tasks.

Property Value
Responsibility Web Administrator

ID
SV-33131r1_rule
Version
WG235 W22
Severity
High
Updated

Remediation Templates

A Manual Procedure

Use only secure encrypted logons and connections for uploading files to the web site.