| Checked | Name | Title |
|---|---|---|
| ☐ | SV-256645r888457_rule | VAMI must limit the number of simultaneous requests. |
| ☐ | SV-256646r888460_rule | VAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections. |
| ☐ | SV-256647r888463_rule | VAMI must use cryptography to protect the integrity of remote sessions. |
| ☐ | SV-256648r888466_rule | VAMI must be configured to monitor remote access. |
| ☐ | SV-256649r888469_rule | VAMI must generate log records for system startup and shutdown. |
| ☐ | SV-256650r888472_rule | VAMI must produce log records containing sufficient information to establish what type of events occurred. |
| ☐ | SV-256651r918984_rule | VAMI log files must only be accessible by privileged users. |
| ☐ | SV-256652r888478_rule | The rsyslog must be configured to monitor VAMI logs. |
| ☐ | SV-256653r888481_rule | VAMI server binaries and libraries must be verified for their integrity. |
| ☐ | SV-256654r888484_rule | VAMI must only load allowed server modules. |
| ☐ | SV-256655r888487_rule | VAMI must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled. |
| ☐ | SV-256656r888490_rule | VAMI must explicitly disable Multipurpose Internet Mail Extensions (MIME) mime mappings based on "Content-Type". |
| ☐ | SV-256657r888493_rule | VAMI must remove all mappings to unused scripts. |
| ☐ | SV-256658r918987_rule | VAMI must have resource mappings set to disable the serving of certain file types. |
| ☐ | SV-256659r888499_rule | VAMI must not have the Web Distributed Authoring (WebDAV) servlet installed. |
| ☐ | SV-256660r888502_rule | VAMI must prevent hosted applications from exhausting system resources. |
| ☐ | SV-256661r888505_rule | VAMI must protect the keystore from unauthorized access. |
| ☐ | SV-256662r888508_rule | VAMI must protect against or limit the effects of HTTP types of denial-of-service (DoS) attacks. |
| ☐ | SV-256663r888511_rule | VAMI must set the encoding for all text Multipurpose Internet Mail Extensions (MIME) types to UTF-8. |
| ☐ | SV-256664r888514_rule | VAMI must disable directory browsing. |
| ☐ | SV-256665r888517_rule | VAMI must not be configured to use "mod_status". |
| ☐ | SV-256666r888520_rule | VAMI must have debug logging disabled. |
| ☐ | SV-256667r888523_rule | VAMI must be protected from being stopped by a nonprivileged user. |
| ☐ | SV-256668r888526_rule | VAMI must implement Transport Layer Security (TLS) 1.2 exclusively. |
| ☐ | SV-256669r888529_rule | VAMI must force clients to select the most secure cipher. |
| ☐ | SV-256670r888532_rule | VAMI must disable client-initiated Transport Layer Security (TLS) renegotiation. |
| ☐ | SV-256671r888535_rule | VAMI must be configured to hide the server type and version in client responses. |
| ☐ | SV-256672r888538_rule | VAMI must enable FIPS mode. |