| Checked | Name | Title |
|---|
| ☐ | SV-279030r1171489_rule | ColdFusion must limit concurrent sessions to the Administrator Console. |
| ☐ | SV-279031r1171492_rule | The ColdFusion built-in Tomcat Web Server must use FIPS-validated ciphers on secured connectors. |
| ☐ | SV-279032r1171325_rule | ColdFusion must require enforced authentication. |
| ☐ | SV-279033r1171269_rule | ColdFusion must not have local users. |
| ☐ | SV-279034r1171436_rule | ColdFusion must produce log records containing information to establish what type of events occurred. |
| ☐ | SV-279035r1171616_rule | ColdFusion must log scheduled tasks. |
| ☐ | SV-279036r1171601_rule | The ColdFusion log information must be protected from any type of unauthorized read access by having file ownership set properly. |
| ☐ | SV-279037r1171603_rule | The ColdFusion file ownership and permissions must be restricted to prevent unauthorized access to log tools. |
| ☐ | SV-279038r1171464_rule | Before installing or upgrading ColdFusion, the integrity of the installation package must be manually verified. |
| ☐ | SV-279039r1171605_rule | Critical ColdFusion directories must have secure file system permissions and ownership. |
| ☐ | SV-279040r1171341_rule | ColdFusion must configure WebSocket Service. |
| ☐ | SV-279041r1171343_rule | ColdFusion must have Event Gateway Services disabled when not in use. |
| ☐ | SV-279042r1171505_rule | ColdFusion must have Remote Development Services (RDS) disabled. |
| ☐ | SV-279043r1171348_rule | ColdFusion must have example services removed. |
| ☐ | SV-279044r1171508_rule | ColdFusion must disable all remote and client-side debugging features, including Remote Inspection, Robust Exception Information, AJAX Debug Log Window, and Line Debugging. |
| ☐ | SV-279045r1171287_rule | ColdFusion must have any unused mappings removed. |
| ☐ | SV-279046r1171510_rule | ColdFusion must have Central Configuration Server (CCS) disabled. |
| ☐ | SV-279047r1171513_rule | ColdFusion must have only approved Tomcat connectors enabled. |
| ☐ | SV-279048r1171516_rule | ColdFusion must have Tomcat configured with deployXML disabled. |
| ☐ | SV-279049r1171519_rule | ColdFusion must be configured with autoDeploy disabled. |
| ☐ | SV-279050r1171521_rule | ColdFusion must be configured with secure and approved server settings to enforce application hardening, input validation, error handling, and protection against common web vulnerabilities. |
| ☐ | SV-279051r1171473_rule | ColdFusion must have the sample data directories removed. |
| ☐ | SV-279052r1171523_rule | ColdFusion must have the CFSTAT feature disabled when not in use. |
| ☐ | SV-279053r1171525_rule | ColdFusion must disable the In-Memory File System. |
| ☐ | SV-279054r1171443_rule | ColdFusion must restrict unauthorized remote access to the ColdFusion Administrator Console and ensure all ports used are approved and properly secured. |
| ☐ | SV-279055r1171527_rule | ColdFusion must be using an enterprise solution for authentication. |
| ☐ | SV-279056r1171606_rule | Web services using Simple Object Access Protocol (SOAP) to access sensitive data must be secured with WS-Security. |
| ☐ | SV-279057r1171529_rule | ColdFusion must store only encrypted representations of passwords. |
| ☐ | SV-279058r1207648_rule | ColdFusion must transmit only encrypted representations of passwords to NoSQL data sources. |
| ☐ | SV-279059r1207648_rule | ColdFusion must only transmit encrypted representations of passwords to the Solr Server. |
| ☐ | SV-279060r1207648_rule | ColdFusion must transmit only encrypted representations of passwords to the mail server. |
| ☐ | SV-279061r1207648_rule | ColdFusion must only transmit encrypted representations of passwords to the caching server. |
| ☐ | SV-279062r1207648_rule | JVM Arguments must be configured for encryption. |
| ☐ | SV-279063r1171542_rule | ColdFusion must be configured to use only DOD-approved keystores and truststores containing certificates issued by a DOD Public Key Infrastructure (PKI) Certificate Authority (CA), and all keystore and truststore files must be protected by file system permissions that prevent unauthorized access or modification. |
| ☐ | SV-279064r1171544_rule | The ColdFusion Administrator Console must be hosted on a management network. |
| ☐ | SV-279065r1171383_rule | ColdFusion must have sandboxes enabled and defined. |
| ☐ | SV-279066r1171607_rule | ColdFusion must separate the hosted application from the web server. |
| ☐ | SV-279067r1171547_rule | ColdFusion must be configured to mutually authenticate connecting proxies and load balancers. |
| ☐ | SV-279068r1172825_rule | ColdFusion must generate a unique session identifier using a FIPS 140-2/140-3 or higher approved random number generator. |
| ☐ | SV-279069r1171551_rule | ColdFusion systems must provide clustering. |
| ☐ | SV-279070r1172833_rule | ColdFusion must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications. |
| ☐ | SV-279071r1171608_rule | ColdFusion must have the Tomcat DefaultServlet debug parameter disabled. |
| ☐ | SV-279072r1170990_rule | The ColdFusion error messages must be restricted to only authorized users. |
| ☐ | SV-279073r1171560_rule | ColdFusion must set a maximum session timeout value. |
| ☐ | SV-279074r1171609_rule | ColdFusion must control remote access to the Administrator Console. |
| ☐ | SV-279075r1171564_rule | ColdFusion must control remote access to Exposed Services. |
| ☐ | SV-279076r1172835_rule | ColdFusion must allocate log record storage capacity. |
| ☐ | SV-279077r1171570_rule | ColdFusion must record time stamps for log records that can be mapped system time. |
| ☐ | SV-279078r1172827_rule | For PKI-based authentication, ColdFusion must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. |
| ☐ | SV-279079r1171576_rule | ColdFusion must set Request Tuning configurations. |
| ☐ | SV-279080r1171402_rule | ColdFusion must limit the maximum number of threads available for CFTHREAD. |
| ☐ | SV-279081r1171481_rule | ColdFusion must limit the maximum number of Web Service requests. |
| ☐ | SV-279082r1171310_rule | ColdFusion must limit the maximum number of ColdFusion Component (CFC) function requests. |
| ☐ | SV-279083r1171449_rule | ColdFusion must configure Data Sources to limit SQL command and configure timeout. |
| ☐ | SV-279084r1171578_rule | ColdFusion must not store user information in the server registry. |
| ☐ | SV-279085r1171029_rule | ColdFusion must limit the in-memory size of the virtual file system. |
| ☐ | SV-279086r1171032_rule | ColdFusion must limit the default maximum thread count for parallel functions. |
| ☐ | SV-279087r1171035_rule | ColdFusion must limit the maximum post data size. |
| ☐ | SV-279088r1171038_rule | ColdFusion must limit the request throttle memory. |
| ☐ | SV-279089r1171580_rule | ColdFusion must set an organization defined maximum number of cached templates. |
| ☐ | SV-279090r1171582_rule | ColdFusion must set an organization defined maximum JVM heap size. |
| ☐ | SV-279091r1171452_rule | ColdFusion must set a nonzero timeout for web services. |
| ☐ | SV-279092r1171584_rule | JVM Arguments must be configured for Transport Layer Security (TLS) 1.2 or higher. |
| ☐ | SV-279093r1171053_rule | ColdFusion must configure Lightweight Directory Access Protocol (LDAP) for Transport Layer Security (TLS). |
| ☐ | SV-279094r1171587_rule | ColdFusion must remove all export ciphers to protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-279095r1171617_rule | JVM arguments must be configured to use approved cryptographic mechanisms to protect data in transit. |
| ☐ | SV-279096r1171589_rule | ColdFusion must encrypt patch retrieval. |
| ☐ | SV-279097r1171591_rule | ColdFusion must ensure that ColdFusion Package Manager (cfpm) packages are transmitted using encrypted protocols. |
| ☐ | SV-279098r1172830_rule | The ColdFusion administrator must be using HTTPS to maintain the confidentiality and integrity of information during reception. |
| ☐ | SV-279099r1172837_rule | ColdFusion Backup Directory must be deleted. |
| ☐ | SV-279100r1171595_rule | ColdFusion must be set to automatically check for updates. |
| ☐ | SV-279101r1171077_rule | ColdFusion must have notifications enabled when a server update is available. |
| ☐ | SV-279102r1171420_rule | Installed versions of ColdFusion must be supported by the vendor. |
| ☐ | SV-279103r1171485_rule | ColdFusion must execute as a nonprivileged user. |
| ☐ | SV-279104r1171486_rule | The ColdFusion Root Administrator account must have a unique username. |
| ☐ | SV-279105r1171428_rule | ColdFusion must protect newly created objects. |
| ☐ | SV-279106r1171597_rule | ColdFusion must be configured to set the cookie settings. |
| ☐ | SV-279107r1208176_rule | ColdFusion must be configured to enable Cross-Origin Resource Sharing (CORS) to allow mobile applications to access resources from different origins securely. |
| ☐ | SV-279108r1171098_rule | ColdFusion must be configured to set the HTTPOnly attribute on session cookies to prevent client-side scripts from accessing the cookies. |
| ☐ | SV-279109r1171101_rule | ColdFusion must be configured to set the Secure attribute on session cookies to ensure that cookies are only transmitted over secure HTTPS connections. |
| ☐ | SV-279110r1171432_rule | ColdFusion must have the Java Runtime Environment (JRE) updated to the latest version. |
| ☐ | SV-279111r1171107_rule | ColdFusion must have CFIDE blocked in the uriworkermap.properties file. |
| ☐ | SV-279112r1171599_rule | ColdFusion must include only approved trust anchors in trust stores or certificate stores managed by the organization. |
| ☐ | SV-279129r1171553_rule | ColdFusion must not install the Performance Monitoring Toolset (PMT) Agent Package. |