Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000001-WSR-000002

    Group
  • The Apache web server must perform server-side session management.

    Session management is the practice of protecting the bulk of the user authorization and identity information. This data can be stored on the client system or on the server. When the session info...
    Rule Medium Severity
  • SRG-APP-000014-WSR-000006

    Group
  • The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.

    The Apache web server has several remote communications channels. Examples are user requests via http/https, communication to a backend database, and communication to authenticate users. The encryp...
    Rule Medium Severity
  • SRG-APP-000095-WSR-000056

    Group
  • The Apache web server must produce log records containing sufficient information to establish what type of events occurred.

    Apache web server logging capability is critical for accurate forensic analysis. Without sufficient and accurate information, a correct replay of the events cannot be determined. Ascertaining th...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000015

    Group
  • The Apache web server must not perform user management for hosted applications.

    User management and authentication can be an essential part of any application hosted by the web server. Along with authenticating users, the user management function must perform several other tas...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000081

    Group
  • The Apache web server must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled.

    Controlling what a user of a hosted application can access is part of the security posture of the web server. Any time a user can access more functionality than is needed for the operation of the h...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules