Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule info_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule include_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule autoindex_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the IndexOptions directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the AddIconByEncoding directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the AddIconByType directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the AddIcon directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the DefaultIcon directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the ReadmeName directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabili...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the HeaderName directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the IndexIgnore directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule dir_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabili...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the DirectoryIndex directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabili...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule cgi_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule fastcgi_module disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule cgid_module directive disabled for mpm workers.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the IfModule cgid_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule mpm_winnt_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the ScriptAlias directive for CGI scripts disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the ScriptSock directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the cgi-bin directory disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have directives pertaining to certain scripting languages removed from virtual hosts.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule asis_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule imagemap_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Low Severity
  • SRG-APP-000141-WSR-000075

    Group
  • OHS must have the LoadModule actions_module directive disabled.

    A web server can provide many features, services, and processes. Some of these may be deemed unnecessary or too unsecure to run on a production DoD system. The web server must provide the capabil...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules