III - Administrative Sensitive
Rules and Groups employed by this XCCDF Profile
-
WG360
<GroupDescription></GroupDescription>Group -
Symbolic links must not be used in the web content directory tree.
<VulnDiscussion>A symbolic link allows a file or a directory to be referenced using a symbolic name raising a potential hazard if symbolic li...Rule High Severity -
WG400
<GroupDescription></GroupDescription>Group -
All interactive programs (CGI) must be placed in a designated directory with appropriate permissions.
<VulnDiscussion>CGI scripts represents one of the most common and exploitable means of compromising a web server. By definition, CGI are exec...Rule Medium Severity -
WG110
<GroupDescription></GroupDescription>Group -
The number of allowed simultaneous requests must be set.
<VulnDiscussion>Resource exhaustion can occur when an unlimited number of concurrent requests are allowed on a web site, facilitating a denia...Rule Medium Severity -
WG170
<GroupDescription></GroupDescription>Group -
Each readable web document directory must contain either a default, home, index, or equivalent file.
<VulnDiscussion>The goal is to completely control the web users experience in navigating any portion of the web document root directories. En...Rule Low Severity -
WG230
<GroupDescription></GroupDescription>Group -
Web server administration must be performed over a secure path or at the local console.
<VulnDiscussion>Logging into a web server remotely using an unencrypted protocol or service when performing updates and maintenance is a majo...Rule High Severity -
WG240
<GroupDescription></GroupDescription>Group -
Logs of web server access and errors must be established and maintained
<VulnDiscussion>A major tool in exploring the web site use, attempted use, unusual conditions, and problems are reported in the access and er...Rule Medium Severity -
WG250
<GroupDescription></GroupDescription>Group -
Log file access must be restricted to System Administrators, Web Administrators or Auditors.
<VulnDiscussion>A major tool in exploring the web site use, attempted use, unusual conditions, and problems are the access and error logs. In...Rule Medium Severity -
WG260
<GroupDescription></GroupDescription>Group -
Only web sites that have been fully reviewed and tested must exist on a production web server.
<VulnDiscussion>In the case of a production web server, areas for content development and testing will not exist, as this type of content is ...Rule Medium Severity -
WG290
<GroupDescription></GroupDescription>Group -
Web client access to the content directories must be restricted to read and execute.
<VulnDiscussion>Excessive permissions for the anonymous web user account are one of the most common faults contributing to the compromise of ...Rule High Severity -
WG310
<GroupDescription></GroupDescription>Group -
A web site must not contain a robots.txt file.
<VulnDiscussion>Search engines are constantly at work on the Internet. Search engines are augmented by agents, often referred to as spiders ...Rule Medium Severity -
WG340
<GroupDescription></GroupDescription>Group -
A private web server must utilize an approved TLS version.
<VulnDiscussion>Transport Layer Security (TLS) encryption is a required security setting for a private web server. Encryption of private inf...Rule Medium Severity -
WG350
<GroupDescription></GroupDescription>Group -
A private web server will have a valid DoD server certificate.
<VulnDiscussion>This check verifies that DoD is a hosted web site's CA. The certificate is actually a DoD-issued server certificate used by t...Rule Medium Severity -
WG490
<GroupDescription></GroupDescription>Group -
Java software on production web servers must be limited to class files and the JAVA virtual machine.
<VulnDiscussion>From the source code in a .java or a .jpp file, the Java compiler produces a binary file with an extension of .class. The .ja...Rule Low Severity -
WG430
<GroupDescription></GroupDescription>Group -
Anonymous FTP user access to interactive scripts is prohibited.
<VulnDiscussion>The directories containing the CGI scripts, such as PERL, must not be accessible to anonymous users via FTP. This applies to ...Rule Medium Severity -
WG460
<GroupDescription></GroupDescription>Group -
PERL scripts must use the TAINT option.
<VulnDiscussion>PERL (Practical Extraction and Report Language) is an interpreted language optimized for scanning arbitrary text files, extra...Rule Medium Severity -
WG205
<GroupDescription></GroupDescription>Group -
The web document (home) directory must be in a separate partition from the web server’s system files.
<VulnDiscussion>Application partitioning enables an additional security measure by securing user traffic under one security context, while ma...Rule Medium Severity -
WG265
<GroupDescription></GroupDescription>Group -
The required DoD banner page must be displayed to authenticated users accessing a DoD private website.
<VulnDiscussion>A consent banner will be in place to make prospective entrants aware that the website they are about to enter is a DoD web si...Rule Low Severity -
WG140
<GroupDescription></GroupDescription>Group -
Private web servers must require certificates issued from a DoD-authorized Certificate Authority.
<VulnDiscussion>Web sites requiring authentication within the DoD must utilize PKI as an authentication mechanism for web users. Information ...Rule Medium Severity -
WG235
<GroupDescription></GroupDescription>Group -
Web Administrators must only use encrypted connections for Document Root directory uploads.
<VulnDiscussion>Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper e...Rule High Severity -
WG237
<GroupDescription></GroupDescription>Group -
Remote authors or content providers must have all files scanned for viruses and malicious code before uploading files to the Document Root directory.
<VulnDiscussion>Remote web authors should not be able to upload files to the Document Root directory structure without virus checking and che...Rule Medium Severity -
WG242
<GroupDescription></GroupDescription>Group -
Log file data must contain required data elements.
<VulnDiscussion>The use of log files is a critical component of the operation of the Information Systems (IS) used within the DoD, and they c...Rule Medium Severity -
WG255
<GroupDescription></GroupDescription>Group -
Access to the web server log files must be restricted to administrators, web administrators, and auditors.
<VulnDiscussion>A major tool in exploring the web site use, attempted use, unusual conditions, and problems are the access and error logs. In...Rule Medium Severity -
WG342
<GroupDescription></GroupDescription>Group -
Public web servers must use TLS if authentication is required.
<VulnDiscussion>Transport Layer Security (TLS) is optional for a public web server. However, if authentication is being performed, then the ...Rule Medium Severity -
WG610
<GroupDescription></GroupDescription>Group -
Web sites must utilize ports, protocols, and services according to PPSM guidelines.
<VulnDiscussion>Failure to comply with DoD ports, protocols, and services (PPS) requirements can result in compromise of enclave boundary pro...Rule Low Severity -
WA00605
<GroupDescription></GroupDescription>Group -
Error logging must be enabled.
<VulnDiscussion>The server error logs are invaluable because they can also be used to identify potential problems and enable proactive remedi...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.