STIGQter STIGQter: STIG Summary:

Apache Server 2.4 Windows Site Security Technical Implementation Guide

Version: 2

Release: 3 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-214365r960963_ruleThe Apache web server must not perform user management for hosted applications.
SV-214367r960963_ruleThe Apache web server must allow the mappings to unused and vulnerable scripts to be removed.
SV-214368r960963_ruleUsers and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.
SV-214371r961041_ruleOnly authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.
SV-214372r1138072_ruleApache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.
SV-214373r1138073_ruleAnonymous user access to the Apache web server application directories must be prohibited.
SV-214374r1138074_ruleThe Apache web server must separate the hosted applications from hosted Apache web server management functionality.
SV-214376r1043180_ruleCookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.
SV-214380r961122_ruleThe Apache web server must augment re-creation to a stable and known baseline.
SV-214382r961131_ruleThe Apache web server document directory must be in a separate partition from the Apache web servers system files.
SV-214383r961167_ruleThe Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
SV-214388r961278_ruleThe Apache web server must restrict inbound connections from nonsecure zones.
SV-214389r961353_ruleNon-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
SV-214390r1192950_ruleThe Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.
SV-214394r961632_ruleCookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie data.
SV-214395r961632_ruleCookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.