Skip to content

I - Mission Critical Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000357-AS-000038

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.

    &lt;VulnDiscussion&gt;JVM logs are logs used to store application and runtime related events, rather than audit related events. They are mainly use...
    Rule Medium Severity
  • SRG-APP-000380-AS-000088

    <GroupDescription></GroupDescription>
    Group
  • The server.xml file must be protected from unauthorized modification.

    &lt;VulnDiscussion&gt;When dealing with access restrictions pertaining to change control, it should be noted that any changes to the software, and/...
    Rule Medium Severity
  • SRG-APP-000400-AS-000246

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period.

    &lt;VulnDiscussion&gt;Larger authentication cache timeout values can increase security risks. For example, a user who is revoked can still log in b...
    Rule Medium Severity
  • SRG-APP-000428-AS-000265

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server LTPA keys password must be changed.

    &lt;VulnDiscussion&gt;The default location of the automatically generated Lightweight Third Party Authentication (LTPA) keys file is ${server.outpu...
    Rule Medium Severity
  • SRG-APP-000439-AS-000274

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.

    &lt;VulnDiscussion&gt;Export grade encryption suites are not strong and do not meet DoD requirements. The encryption for the session becomes easy f...
    Rule Medium Severity
  • SRG-APP-000440-AS-000167

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must be configured to use HTTPS only.

    &lt;VulnDiscussion&gt;Transmission of data can take place between the application server and a large number of devices/applications external to the...
    Rule Medium Severity
  • SRG-APP-000456-AS-000266

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source.

    &lt;VulnDiscussion&gt;Security vulnerabilities are often addressed by testing and applying the latest security patches and fix packs. The latest fi...
    Rule Medium Severity
  • SRG-APP-000499-AS-000224

    <GroupDescription></GroupDescription>
    Group
  • The WebSphere Liberty Server must generate log records for authentication and authorization events.

    &lt;VulnDiscussion&gt;Enabling authentication (SECURITY_AUTHN) and authorization (SECURITY_AUTHZ) event handlers configures the server to record se...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules