Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • Private web servers must require certificates issued from a DoD-authorized Certificate Authority.

    <VulnDiscussion>Web sites requiring authentication within the DoD must utilize PKI as an authentication mechanism for web users. Information ...
    Rule Medium Severity
  • WG235

    <GroupDescription></GroupDescription>
    Group
  • Web Administrators must only use encrypted connections for Document Root directory uploads.

    &lt;VulnDiscussion&gt;Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper e...
    Rule High Severity
  • WG237

    <GroupDescription></GroupDescription>
    Group
  • Remote authors or content providers must have all files scanned for viruses and malicious code before uploading files to the Document Root directory.

    &lt;VulnDiscussion&gt;Remote web authors should not be able to upload files to the Document Root directory structure without virus checking and che...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules