II - Mission Support Sensitive
Rules and Groups employed by this XCCDF Profile
-
WG340
<GroupDescription></GroupDescription>Group -
A private web server must utilize an approved TLS version.
<VulnDiscussion>Transport Layer Security (TLS) encryption is a required security setting for a private web server. Encryption of private info...Rule Medium Severity -
WG350
<GroupDescription></GroupDescription>Group -
A private web server must have a valid DoD server certificate.
<VulnDiscussion>This check verifies that DoD is a hosted web site's CA. The certificate is actually a DoD-issued server certificate used by t...Rule Medium Severity -
WG490
<GroupDescription></GroupDescription>Group -
Java software on production web servers must be limited to class files and the JAVA virtual machine.
<VulnDiscussion>From the source code in a .java or a .jpp file, the Java compiler produces a binary file with an extension of .class. The .ja...Rule Low Severity -
WG430
<GroupDescription></GroupDescription>Group -
Anonymous FTP user access to interactive scripts must be prohibited.
<VulnDiscussion>The directories containing the CGI scripts, such as PERL, must not be accessible to anonymous users via FTP. This applies to ...Rule Medium Severity -
WG460
<GroupDescription></GroupDescription>Group -
PERL scripts must use the TAINT option.
<VulnDiscussion>PERL (Practical Extraction and Report Language) is an interpreted language optimized for scanning arbitrary text files, extra...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules