Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000001

    Group
  • The web server must limit the number of allowed simultaneous session requests.

    Web server management includes the ability to control the number of users and user sessions that utilize a web server. Limiting the number of allowed users and sessions per user is helpful in limit...
    Rule Medium Severity
  • SRG-APP-000001

    Group
  • The web server must perform server-side session management.

    Session management is the practice of protecting the bulk of the user authorization and identity information. Storing of this data can occur on the client system or on the server. When the sessio...
    Rule Medium Severity
  • SRG-APP-000014

    Group
  • The web server must use encryption strength in accordance with the categorization of data hosted by the web server when remote connections are provided.

    The web server has several remote communications channels. Examples are user requests via http/https, communication to a backend database, or communication to authenticate users. The encryption use...
    Rule Medium Severity
  • SRG-APP-000015

    Group
  • The web server must use cryptography to protect the integrity of remote sessions.

    Data exchanged between the user and the web server can range from static display data to credentials used to log into the hosted application. Even when data appears to be static, the non-displayed ...
    Rule Medium Severity
  • SRG-APP-000016

    Group
  • The web server must generate information to be used by external applications or entities to monitor and control remote access.

    Remote access to the web server is any access that communicates through an external, non-organization-controlled network. Remote access can be used to access hosted applications or to perform manag...
    Rule Medium Severity
  • SRG-APP-000033

    Group
  • The web server must enforce approved authorizations for logical access to hosted applications and resources in accordance with applicable access control policies.

    To control access to sensitive information and hosted applications by entities that have been issued certificates by DoD-approved PKIs, the web server must be properly configured to incorporate a m...
    Rule Medium Severity
  • SRG-APP-000089

    Group
  • The web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.

    Log records can be generated from various components within the web server (e.g., httpd, plug-ins to external backends, etc.). From a web server perspective, certain specific web server functionali...
    Rule Medium Severity
  • SRG-APP-000092

    Group
  • The web server must initiate session logging upon start up.

    An attacker can compromise a web server during the startup process. If logging is not initiated until all the web server processes are started, key information may be missed and not available durin...
    Rule Medium Severity
  • SRG-APP-000095

    Group
  • The web server must produce log records containing sufficient information to establish what type of events occurred.

    Web server logging capability is critical for accurate forensic analysis. Without sufficient and accurate information, a correct replay of the events cannot be determined. For web servers, events...
    Rule Medium Severity
  • SRG-APP-000096

    Group
  • The web server must produce log records containing sufficient information to establish when (date and time) events occurred.

    Web server logging capability is critical for accurate forensic analysis. Without sufficient and accurate information, a correct replay of the events cannot be determined. Ascertaining the correc...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules