Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000097-AS-000060

    <GroupDescription></GroupDescription>
    Group
  • HTTP status code must be logged.

    &lt;VulnDiscussion&gt;The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...
    Rule Low Severity
  • SRG-APP-000097-AS-000060

    <GroupDescription></GroupDescription>
    Group
  • The first line of request must be logged.

    &lt;VulnDiscussion&gt;The access logfile format is defined within a Valve that implements the org.apache.catalina.valves.AccessLogValve interface w...
    Rule Medium Severity
  • SRG-APP-000118-AS-000078

    <GroupDescription></GroupDescription>
    Group
  • $CATALINA_BASE/logs folder permissions must be set to 750.

    &lt;VulnDiscussion&gt;Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...
    Rule Medium Severity
  • SRG-APP-000118-AS-000078

    <GroupDescription></GroupDescription>
    Group
  • Files in the $CATALINA_BASE/logs/ folder must have their permissions set to 640.

    &lt;VulnDiscussion&gt;Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...
    Rule Medium Severity
  • SRG-APP-000119-AS-000079

    <GroupDescription></GroupDescription>
    Group
  • Files in the $CATALINA_BASE/conf/ folder must have their permissions set to 640.

    &lt;VulnDiscussion&gt;Tomcat file permissions must be restricted. The standard configuration is to have all Tomcat files owned by root with group T...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules