STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x Lighttpd Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

Lighttpd files must be verified for their integrity before being added to a production web server.

DISA Rule

SV-99903r1_rule

Vulnerability Number

V-89253

Group Title

SRG-APP-000131-WSR-000051

Rule Version

VRAU-LI-000145

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Verify or validate the web server files for integrity before being implemented the production environment.

Check Contents

Obtain supporting documentation from the ISSO.

Determine whether web server files are verified/validated before being implemented into the production environment.

If the web server files are not verified or validated before being implemented into the production environment, this is a finding.

Vulnerability Number

V-89253

Documentable

False

Rule Version

VRAU-LI-000145

Severity Override Guidance

Obtain supporting documentation from the ISSO.

Determine whether web server files are verified/validated before being implemented into the production environment.

If the web server files are not verified or validated before being implemented into the production environment, this is a finding.

Check Content Reference

M

Target Key

3457

Comments