| Checked | Name | Title |
|---|
| ☐ | SV-250322r960735_rule | Maximum in-memory session count must be set according to application requirements. |
| ☐ | SV-250323r960759_rule | The WebSphere Liberty Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher. |
| ☐ | SV-250324r960762_rule | Security cookies must be set to HTTPOnly. |
| ☐ | SV-250325r1015250_rule | The WebSphere Liberty Server must log remote session and security activity. |
| ☐ | SV-250326r1137578_rule | Users in the REST API admin role must be authorized. |
| ☐ | SV-250327r1043188_rule | The WebSphere Liberty Server must be configured to offload logs to a centralized system. |
| ☐ | SV-250328r960933_rule | The WebSphere Liberty Server must protect log information from unauthorized access or changes. |
| ☐ | SV-250329r960939_rule | The WebSphere Liberty Server must protect log tools from unauthorized access. |
| ☐ | SV-250330r960951_rule | The WebSphere Liberty Server must be configured to encrypt log information. |
| ☐ | SV-250331r960960_rule | The WebSphere Liberty Server must protect software libraries from unauthorized access. |
| ☐ | SV-250332r1043177_rule | The WebSphere Liberty Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-250333r1051118_rule | The WebSphere Liberty Server must use an LDAP user registry. |
| ☐ | SV-250334r1051118_rule | Basic Authentication must be disabled. |
| ☐ | SV-250335r1015469_rule | Multifactor authentication for network access to privileged accounts must be used. |
| ☐ | SV-250336r1015470_rule | The WebSphere Liberty Server must store only encrypted representations of user passwords. |
| ☐ | SV-250337r961029_rule | The WebSphere Liberty Server must use TLS-enabled LDAP. |
| ☐ | SV-250338r961044_rule | The WebSphere Liberty Server must use DoD-issued/signed certificates. |
| ☐ | SV-250339r1193261_rule | The WebSphere Liberty Server must use FIPS 140-2 approved encryption modules when authenticating users and processes. |
| ☐ | SV-250340r1043182_rule | HTTP session timeout must be configured. |
| ☐ | SV-250341r1015252_rule | Application security must be enabled on the WebSphere Liberty Server. |
| ☐ | SV-250342r961353_rule | Users in a reader-role must be authorized. |
| ☐ | SV-250343r961392_rule | The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements. |
| ☐ | SV-250344r961461_rule | The server.xml file must be protected from unauthorized modification. |
| ☐ | SV-250345r961521_rule | The WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period. |
| ☐ | SV-250346r1067567_rule | The WebSphere Liberty Server LTPA keys password must be changed. |
| ☐ | SV-250347r961632_rule | The WebSphere Liberty Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-250348r1137581_rule | The WebSphere Liberty Server must be configured to use HTTPS only. |
| ☐ | SV-250349r1137612_rule | The WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source. |
| ☐ | SV-250350r961812_rule | The WebSphere Liberty Server must generate log records for authentication and authorization events. |
| ☐ | SV-283668r1193262_rule | The WebSphere Liberty Server must use FIPS 140-3-approved encryption modules when authenticating users and processes. |