STIGQter STIGQter: STIG Summary: APACHE 2.2 Site for UNIX Security Technical Implementation Guide Version: 1 Release: 11 Benchmark Date: 25 Jan 2019:

Web server administration must be performed over a secure path or at the local console.

DISA Rule

SV-33023r3_rule

Vulnerability Number

V-2249

Group Title

WG230

Rule Version

WG230 A22

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure the web server's administration is only performed over a secure path.

Check Contents

If web administration is performed remotely the following checks will apply:

If administration of the server is performed remotely, it will only be performed securely by system administrators.

If web site administration or web application administration has been delegated, those users will be documented and approved by the ISSO.

Remote administration must be in compliance with any requirements contained within the Unix Server STIGs, and any applicable network STIGs.

Remote administration of any kind will be restricted to documented and authorized personnel.

All users performing remote administration must be authenticated.

All remote sessions will be encrypted and they will utilize FIPS 140-2 approved protocols.

FIPS 140-2 approved TLS versions include TLS V1.0 or greater.

Vulnerability Number

V-2249

Documentable

False

Rule Version

WG230 A22

Severity Override Guidance

If web administration is performed remotely the following checks will apply:

If administration of the server is performed remotely, it will only be performed securely by system administrators.

If web site administration or web application administration has been delegated, those users will be documented and approved by the ISSO.

Remote administration must be in compliance with any requirements contained within the Unix Server STIGs, and any applicable network STIGs.

Remote administration of any kind will be restricted to documented and authorized personnel.

All users performing remote administration must be authenticated.

All remote sessions will be encrypted and they will utilize FIPS 140-2 approved protocols.

FIPS 140-2 approved TLS versions include TLS V1.0 or greater.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

161

Comments