STIGQter STIGQter: STIG Summary: VMW vRealize Automation 7.x HA Proxy Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

HAProxy files must be verified for their integrity (checksums) before being added to the build systems.

DISA Rule

SV-99799r1_rule

Vulnerability Number

V-89149

Group Title

SRG-APP-000131-WSR-000051

Rule Version

VRAU-HA-000115

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure web server files are verified or validated before being implemented the production environment.

Check Contents

Interview the ISSO.

Determine whether web server files are verified/validated before being implemented into the production environment.

If the web server files are not verified or validated before being implemented into the production environment, this is a finding.

Vulnerability Number

V-89149

Documentable

False

Rule Version

VRAU-HA-000115

Severity Override Guidance

Interview the ISSO.

Determine whether web server files are verified/validated before being implemented into the production environment.

If the web server files are not verified or validated before being implemented into the production environment, this is a finding.

Check Content Reference

M

Target Key

3455

Comments