Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000141-WSR-000085

    <GroupDescription></GroupDescription>
    Group
  • All Automation Controller NGINX web servers must have Web Distributed Authoring (WebDAV) disabled.

    &lt;VulnDiscussion&gt;Automation Controller NGINX web servers can be installed with functionality that, just by its nature, is not secure. Web Dist...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000086

    <GroupDescription></GroupDescription>
    Group
  • All Automation Controller NGINX web servers must protect system resources and privileged operations from hosted applications.

    &lt;VulnDiscussion&gt;Automation Controller NGINX web servers may host too many applications. Each application will need certain system resources a...
    Rule Low Severity
  • SRG-APP-000142-WSR-000089

    <GroupDescription></GroupDescription>
    Group
  • All Automation Controller NGINX web servers must be configured to use a specified IP address and port.

    &lt;VulnDiscussion&gt;From a security perspective, it is important that all Automation Controller NGINX web servers are configured to use a specifi...
    Rule Medium Severity
  • SRG-APP-000176-WSR-000096

    <GroupDescription></GroupDescription>
    Group
  • Only authenticated system administrators or the designated PKI Sponsor for an Automation Controller NGINX web server must have access to any Automation Controller NGINX web server's private key.

    &lt;VulnDiscussion&gt;Each Automation Controller NGINX web server's private key is used to prove the identity of the server to clients and securely...
    Rule Medium Severity
  • SRG-APP-000211-WSR-000030

    <GroupDescription></GroupDescription>
    Group
  • All Automation Controller NGINX web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.

    &lt;VulnDiscussion&gt;AIT is important to limit access to Automation Controller nginx web servers and provide access on a need-to-know basis. For e...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules