STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must be protected from being stopped by a non-privileged user.

DISA Rule

SV-206432r961620_rule

Vulnerability Number

V-206432

Group Title

SRG-APP-000435

Rule Version

SRG-APP-000435-WSR-000147

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove or modify non-privileged account access to the web server process ID and the utilities used for starting/stopping the web server.

Check Contents

Review the web server documentation and deployed configuration to determine where the process ID is stored and which utilities are used to start/stop the web server.

Determine whether the process ID and the utilities are protected from non-privileged users.

If they are not protected, this is a finding.

Vulnerability Number

V-206432

Documentable

False

Rule Version

SRG-APP-000435-WSR-000147

Severity Override Guidance

Review the web server documentation and deployed configuration to determine where the process ID is stored and which utilities are used to start/stop the web server.

Determine whether the process ID and the utilities are protected from non-privileged users.

If they are not protected, this is a finding.

Check Content Reference

M

Target Key

2910