STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

Classified web servers will be afforded physical security commensurate with the classification of its content.

DISA Rule

SV-33015r2_rule

Vulnerability Number

V-13591

Group Title

WA155

Rule Version

WA155 W22

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Relocate the web server to a location appropriate to classified devices.

Check Contents

The reviewer should query the ISSO, the SA, the web administrator, or developers as necessary to determine if a classified web server is afforded physical security commensurate with the classification of its content (i.e., is located in a vault or a room approved for classified storage at the highest classification processed on that system).

Ask what the classification of the web server is, and based on the classification, evaluate the location of the web server to determine if it is approved for storage of that classification level.

If the web server is not appropriately physically protected based on its classification, this is a finding.

Vulnerability Number

V-13591

Documentable

False

Rule Version

WA155 W22

Severity Override Guidance

The reviewer should query the ISSO, the SA, the web administrator, or developers as necessary to determine if a classified web server is afforded physical security commensurate with the classification of its content (i.e., is located in a vault or a room approved for classified storage at the highest classification processed on that system).

Ask what the classification of the web server is, and based on the classification, evaluate the location of the web server to determine if it is approved for storage of that classification level.

If the web server is not appropriately physically protected based on its classification, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Officer

Target Key

158

Comments