Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000141-WSR-000085

    Group
  • All Automation Controller NGINX web servers must have Web Distributed Authoring (WebDAV) disabled.

    Automation Controller NGINX web servers can be installed with functionality that, just by its nature, is not secure. Web Distributed Authoring (WebDAV) is an extension to the HTTP protocol that, wh...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000086

    Group
  • All Automation Controller NGINX web servers must protect system resources and privileged operations from hosted applications.

    Automation Controller NGINX web servers may host too many applications. Each application will need certain system resources and privileged operations to operate correctly. The Automation Controller...
    Rule Low Severity
  • SRG-APP-000142-WSR-000089

    Group
  • All Automation Controller NGINX web servers must be configured to use a specified IP address and port.

    From a security perspective, it is important that all Automation Controller NGINX web servers are configured to use a specified IP address and port because “listening” on all IP addresses poses a v...
    Rule Medium Severity
  • SRG-APP-000176-WSR-000096

    Group
  • Only authenticated system administrators or the designated PKI Sponsor for an Automation Controller NGINX web server must have access to any Automation Controller NGINX web server's private key.

    Each Automation Controller NGINX web server's private key is used to prove the identity of the server to clients and securely exchange the shared secret key used to encrypt communications between t...
    Rule Medium Severity
  • SRG-APP-000211-WSR-000030

    Group
  • All Automation Controller NGINX web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.

    AIT is important to limit access to Automation Controller nginx web servers and provide access on a need-to-know basis. For example, only System Administrators must have access to all the system's ...
    Rule Medium Severity
  • SRG-APP-000223-WSR-000011

    Group
  • Cookies exchanged between any Automation Controller NGINX web server and any client, such as session cookies, must have security settings that disallow cookie access outside the originating Automation Controller NGINX web server and hosted application.

    It is important that cookies exchanged between any Automation Controller NGINX webserver and any client have security settings that do not allow cookie access outside the originating Automation Con...
    Rule Medium Severity
  • SRG-APP-000233-WSR-000146

    Group
  • The Automation Controller NGINX web server document directory must be in a separate partition from the web server's system files.

    It is important that Automation Controller NGINX web server restricts the ability of clients to launch denial-of-service (DoS) attacks against other information systems or networks by disallowing a...
    Rule Medium Severity
  • SRG-APP-000251-WSR-000157

    Group
  • The Automation Controller NGINX web server must limit the character set used for data entry.

    It is important that Automation Controller NGINX web server limit the character set used for data entry and disallow Unicode use in hosted applications to avoid application compromise. Definition o...
    Rule Medium Severity
  • SRG-APP-000266-WSR-000142

    Group
  • The Automation Controller NGINX web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.

    It is important that Automation Controller NGINX web server display a default hosted application web paged and not a directory listing when a requested web page cannot be found, because the web ser...
    Rule Medium Severity
  • SRG-APP-000266-WSR-000160

    Group
  • Debugging and trace information, within Automation Controller NGINX web server, used to diagnose the web server must be disabled.

    It is important that Automation Controller NGINX web server debugging and trace information used to diagnose the web server is disabled, because debugging information can yield information about th...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules