I - Mission Critical Classified
Rules and Groups employed by this XCCDF Profile
-
Private web servers must require certificates issued from a DoD-authorized Certificate Authority.
Web sites requiring authentication within the DoD must utilize PKI as an authentication mechanism for web users. Information systems residing behind web servers requiring authorization based on ind...Rule Medium Severity -
WG235
Group -
Web Administrators must only use encrypted connections for Document Root directory uploads.
Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An enc...Rule High Severity -
WG242
Group -
Log file data must contain required data elements.
The use of log files is a critical component of the operation of the Information Systems (IS) used within the DoD, and they can provide invaluable assistance with regard to damage assessment, causa...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules