I - Mission Critical Classified
Rules and Groups employed by this XCCDF Profile
-
WG340
Group -
A private web server must utilize an approved TLS version.
Transport Layer Security (TLS) encryption is a required security setting for a private web server. Encryption of private information is essential to ensuring data confidentiality. If private inform...Rule Medium Severity -
WG350
Group -
A private web server must have a valid DoD server certificate.
This check verifies that DoD is a hosted web site's CA. The certificate is actually a DoD-issued server certificate used by the organization being reviewed. This is used to verify the authenticity ...Rule Medium Severity -
WG490
Group -
Java software on production web servers must be limited to class files and the JAVA virtual machine.
From the source code in a .java or a .jpp file, the Java compiler produces a binary file with an extension of .class. The .java or .jpp file would, therefore, reveal sensitive information regarding...Rule Low Severity -
WG430
Group -
Anonymous FTP user access to interactive scripts must be prohibited.
The directories containing the CGI scripts, such as PERL, must not be accessible to anonymous users via FTP. This applies to all directories that contain scripts that can dynamically produce web pa...Rule Medium Severity -
WG460
Group -
PERL scripts must use the TAINT option.
PERL (Practical Extraction and Report Language) is an interpreted language optimized for scanning arbitrary text files, extracting information from those text files, and printing reports based on t...Rule Medium Severity -
WG205
Group -
The web document (home) directory must be in a separate partition from the web server’s system files.
Application partitioning enables an additional security measure by securing user traffic under one security context, while managing system and application files under another. Web content is access...Rule Medium Severity -
WG265
Group -
The required DoD banner page must be displayed to authenticated users accessing a DoD private website.
A consent banner will be in place to make prospective entrants aware that the website they are about to enter is a DoD web site and their activity is subject to monitoring. The document, DoDI 8500....Rule Low Severity -
WG140
Group -
Private web servers must require certificates issued from a DoD-authorized Certificate Authority.
Web sites requiring authentication within the DoD must utilize PKI as an authentication mechanism for web users. Information systems residing behind web servers requiring authorization based on ind...Rule Medium Severity -
WG235
Group -
Web Administrators must only use encrypted connections for Document Root directory uploads.
Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An enc...Rule High Severity -
WG242
Group -
Log file data must contain required data elements.
The use of log files is a critical component of the operation of the Information Systems (IS) used within the DoD, and they can provide invaluable assistance with regard to damage assessment, causa...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.