STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

The Timeout directive must be properly set.

DISA Rule

SV-32980r3_rule

Vulnerability Number

V-13724

Group Title

WA000-WWA020

Rule Version

WA000-WWA020 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify the Timeout directive in the applicable Apache configuration files to have a value of 300 seconds or less.

Check Contents

NOTE: This setting must be explicitly set.

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Timeout

Every enabled Timeout directive value needs to be 300 or less. If any directive is set improperly, this is a finding.

NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for the use of an increased value. If the site has this documented, this should be marked as Not a Finding.

Vulnerability Number

V-13724

Documentable

False

Rule Version

WA000-WWA020 W22

Severity Override Guidance

NOTE: This setting must be explicitly set.

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Timeout

Every enabled Timeout directive value needs to be 300 or less. If any directive is set improperly, this is a finding.

NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for the use of an increased value. If the site has this documented, this should be marked as Not a Finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments