Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000357-AS-000038

    Group
  • The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.

    JVM logs are logs used to store application and runtime related events, rather than audit related events. They are mainly used to diagnose application or runtime bugs. However, they are useful for ...
    Rule Medium Severity
  • SRG-APP-000380-AS-000088

    Group
  • The server.xml file must be protected from unauthorized modification.

    When dealing with access restrictions pertaining to change control, it should be noted that any changes to the software, and/or application server configuration could potentially have significant a...
    Rule Medium Severity
  • SRG-APP-000400-AS-000246

    Group
  • The WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period.

    Larger authentication cache timeout values can increase security risks. For example, a user who is revoked can still log in by using a credential that is cached in the authentication cache until th...
    Rule Medium Severity
  • SRG-APP-000428-AS-000265

    Group
  • The WebSphere Liberty Server LTPA keys password must be changed.

    The default location of the automatically generated Lightweight Third Party Authentication (LTPA) keys file is ${server.output.dir}/resources/security/ltpa.keys. The LTPA keys are encrypted with ...
    Rule Medium Severity
  • SRG-APP-000439-AS-000274

    Group
  • The WebSphere Liberty Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.

    Export grade encryption suites are not strong and do not meet DoD requirements. The encryption for the session becomes easy for the attacker to break. Do not use export grade encryption.
    Rule Medium Severity
  • SRG-APP-000440-AS-000167

    Group
  • The WebSphere Liberty Server must be configured to use HTTPS only.

    Transmission of data can take place between the application server and a large number of devices/applications external to the application server. Examples are a web client used by a user, a backend...
    Rule Medium Severity
  • SRG-APP-000456-AS-000266

    Group
  • The WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source.

    Security vulnerabilities are often addressed by testing and applying the latest security patches and fix packs. The latest fixpacks can be found at: http://www-01.ibm.com/support/docview.wss?uid=sw...
    Rule Medium Severity
  • SRG-APP-000499-AS-000224

    Group
  • The WebSphere Liberty Server must generate log records for authentication and authorization events.

    Enabling authentication (SECURITY_AUTHN) and authorization (SECURITY_AUTHZ) event handlers configures the server to record security authorization and authentication events. By logging these events,...
    Rule Medium Severity
  • SRG-APP-000001-AS-000001

    Group
  • Maximum in-memory session count must be set according to application requirements.

    Application management includes the ability to control the number of sessions that use an application by all accounts and/or account types. Limiting the number of allowed sessions is helpful in lim...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules