STIGQter STIGQter: STIG Summary:

IBM WebSphere Traditional V9.x Security Technical Implementation Guide

Version: 2

Release: 1 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-255818r960735_ruleThe WebSphere Application Server maximum in-memory session count must be set according to application requirements.
SV-255819r1043182_ruleThe WebSphere Application Server admin console session timeout must be configured.
SV-255820r960765_ruleThe WebSphere Application Server security auditing must be enabled.
SV-255821r960765_ruleThe WebSphere Application Server groups in the user registry mapped to WebSphere auditor roles must be configured in accordance with the security plan.
SV-255822r960765_ruleThe WebSphere Application Server users in the WebSphere auditor role must be configured in accordance with the System Security Plan.
SV-255823r960765_ruleThe WebSphere Application Server audit event type filters must be configured.
SV-255824r960765_ruleThe WebSphere Application Server audit service provider must be enabled.
SV-255825r960765_ruleThe WebSphere Application Server automatic repository checkpoints must be enabled to track configuration changes.
SV-255826r961278_ruleThe WebSphere Application Server administrative security must be enabled.
SV-255827r961863_ruleThe WebSphere Application Server bus security must be enabled.
SV-255828r961278_ruleThe WebSphere Application Server users in a local user registry group must be authorized for that group.
SV-255829r960759_ruleThe WebSphere Application Server Quality of Protection (QoP) must be set to use TLSv1.2 or higher.
SV-255830r960759_ruleThe WebSphere Application Server global application security must be enabled.
SV-255831r960759_ruleThe WebSphere Application Server Single Sign On (SSO) must have SSL enabled for Web and SIP Security.
SV-255832r960762_ruleThe WebSphere Application Server security cookies must be set to HTTPOnly.
SV-255833r1137578_ruleThe WebSphere Application Server Java 2 security must be enabled.
SV-255834r1137578_ruleThe WebSphere Application Server Java 2 security must not be bypassed.
SV-255835r1137578_ruleThe WebSphere Application Server users in the admin role must be authorized.
SV-255836r1137578_ruleThe WebSphere Application Server LDAP groups must be authorized for the WebSphere role.
SV-255837r961353_ruleThe WebSphere Application Server users in a LDAP user registry group must be authorized for that group.
SV-255838r960843_ruleThe WebSphere Application Server management interface must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
SV-255839r960846_ruleThe WebSphere Application Server management interface must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
SV-255840r960885_ruleThe WebSphere Application Server must generate log records when successful/unsuccessful attempts to access subject privileges occur.
SV-255841r961392_ruleThe WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
SV-255842r961392_ruleThe WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirements.
SV-255843r961401_ruleThe WebSphere Application Server must provide an immediate real-time alert to authorized users of all log failure events requiring real-time alerts.
SV-255844r960912_ruleThe WebSphere Application Server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
SV-255845r960912_ruleThe WebSphere Application Server audit subsystem failure action must be set to Log warning.
SV-255846r1043188_ruleThe WebSphere Application Server must shut down by default upon log failure (unless availability is an overriding concern).
SV-255847r1043188_ruleThe WebSphere Application Server high availability applications must be configured to fail over to another system in the event of log subsystem failure.
SV-255848r960930_ruleThe WebSphere Application Server must be configured to protect log information from any type of unauthorized read access.
SV-255849r960933_ruleThe WebSphere Application Server must protect log information from unauthorized modification.
SV-255850r960936_ruleThe WebSphere Application Server must protect log information from unauthorized deletion.
SV-255851r960939_ruleThe WebSphere Application Server wsadmin file must be protected from unauthorized access.
SV-255852r960942_ruleThe WebSphere Application Server wsadmin file must be protected from unauthorized modification.
SV-255853r960945_ruleThe WebSphere Application Server wsadmin file must be protected from unauthorized deletion.
SV-255854r960951_ruleThe WebSphere Application Server must be configured to encrypt log information.
SV-255855r960951_ruleThe WebSphere Application Server must be configured to sign log information.
SV-255856r960963_ruleThe WebSphere Application Server process must not be started from the command line with the -password option.
SV-255857r960963_ruleThe WebSphere Application Server files must be owned by the non-root WebSphere user ID.
SV-255858r960963_ruleThe WebSphere Application Server sample applications must be removed.
SV-255859r960963_ruleThe WebSphere Application Server must remove JREs left by web server and plug-in installers for web servers and plugins running in the DMZ.
SV-255860r960963_ruleThe WebSphere Application Server must be run as a non-admin user.
SV-255861r960963_ruleThe WebSphere Application Server must disable JSP class reloading.
SV-255862r1043177_ruleThe WebSphere Application Server must prohibit or restrict the use of nonsecure ports, protocols, modules, and/or services as defined in the PPSM CAL and vulnerability assessments.
SV-255863r1051118_ruleThe WebSphere Application Server LDAP user registry must be used.
SV-255864r1051118_ruleThe WebSphere Application Server local file-based user registry must not be used.
SV-255865r960972_ruleThe WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
SV-255866r960993_ruleThe WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
SV-255867r960993_ruleThe WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.
SV-255868r961863_ruleThe WebSphere Application Server must authenticate all network-connected endpoint devices before establishing any connection.
SV-255869r961863_ruleThe WebSphere Application Server must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
SV-255870r961029_ruleThe WebSphere Application Server application security must be enabled for each security domain except for publicly available applications specified in the System Security Plan.
SV-255871r961029_ruleThe WebSphere Application Server secure LDAP (LDAPS) must be used for authentication.
SV-255872r961521_ruleThe WebSphere Application Server must prohibit the use of cached authenticators after an organization-defined time period.
SV-255873r961041_ruleThe WebSphere Application Server default keystore passwords must be changed.
SV-255874r961044_ruleThe WebSphere Application Server must use signer for DoD-issued certificates.
SV-255875r1193273_ruleThe WebSphere Application Server must utilize FIPS 140-2-approved encryption modules when authenticating users and processes.
SV-255876r961527_ruleThe WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.
SV-255877r1137585_ruleThe WebSphere Application Server must use DoD-approved Signer Certificates.
SV-255878r1137579_ruleThe WebSphere Application Servers must not be in the DMZ.
SV-255879r1043178_ruleThe WebSphere Application Server DoD root CAs must be in the trust store.
SV-255880r961596_ruleThe WebSphere Application Server personal certificates in all keystores must be issued by an approved DoD CA.
SV-255881r961122_ruleThe WebSphere Application Server must be configured to perform complete application deployments when using A/B clusters.
SV-255882r961122_ruleThe WebSphere Application servers with an RMF categorization of high must be in a high-availability (HA) cluster.
SV-255883r1067567_ruleThe WebSphere Application Server must not generate LTPA keys automatically.
SV-255884r1067567_ruleThe WebSphere Application Server must periodically regenerate LTPA keys.
SV-255885r961620_ruleThe WebSphere Application Server high availability applications must be installed on a cluster.
SV-255886r961620_ruleThe WebSphere Application Server memory session settings must be defined according to application load requirements.
SV-255887r961620_ruleThe WebSphere Application Server thread pool size must be defined according to application load requirements.
SV-255888r961632_ruleThe WebSphere Application Server must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
SV-255889r961863_ruleThe WebSphere Application Server distribution and consistency services (DCS) transport links must be encrypted.
SV-255890r1137581_ruleThe WebSphere Application Server plugin must be configured to use HTTPS only.
SV-255891r961677_ruleThe WebSphere Application Server must remove organization-defined software components after updated versions have been installed.
SV-255892r1137612_ruleThe WebSphere Application Server must apply the latest security fixes.
SV-255893r1137612_ruleThe WebSphere Application Server must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVMs, CTOs, DTMs, and STIGs).
SV-283677r1193276_ruleThe WebSphere Application Server must use FIPS 140-3-approved encryption modules when authenticating users and processes.