STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

Non-privileged accounts on the hosting system must only access web server security-relevant information and functions through a distinct administrative account.

DISA Rule

SV-206419r961353_rule

Vulnerability Number

V-206419

Group Title

SRG-APP-000340

Rule Version

SRG-APP-000340-WSR-000029

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set up accounts and roles that can be used to perform web server security-relevant tasks and remove or modify non-privileged account access to security-relevant tasks.

Check Contents

Review the web server documentation and configuration to determine if accounts used for administrative duties of the web server are separated from non-privileged accounts.

If non-privileged accounts can access web server security-relevant information, this is a finding.

Vulnerability Number

V-206419

Documentable

False

Rule Version

SRG-APP-000340-WSR-000029

Severity Override Guidance

Review the web server documentation and configuration to determine if accounts used for administrative duties of the web server are separated from non-privileged accounts.

If non-privileged accounts can access web server security-relevant information, this is a finding.

Check Content Reference

M

Target Key

2910