| Checked | Name | Title |
|---|---|---|
| ☐ | SV-256706r888709_rule | Lookup Service must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-256707r888712_rule | Lookup Service must limit the number of concurrent connections permitted. |
| ☐ | SV-256708r888715_rule | Lookup Service must limit the maximum size of a POST request. |
| ☐ | SV-256709r888718_rule | Lookup Service must protect cookies from cross-site scripting (XSS). |
| ☐ | SV-256710r888721_rule | Lookup Service must record user access in a format that enables monitoring of remote access. |
| ☐ | SV-256711r888724_rule | Lookup Service must generate log records for system startup and shutdown. |
| ☐ | SV-256712r918958_rule | Lookup Service log files must only be accessible by privileged users. |
| ☐ | SV-256713r888730_rule | Lookup Service application files must be verified for their integrity. |
| ☐ | SV-256714r888733_rule | Lookup Service must only run one webapp. |
| ☐ | SV-256715r888736_rule | Lookup Service must not be configured with the "UserDatabaseRealm" enabled. |
| ☐ | SV-256716r888739_rule | Lookup Service must be configured to limit access to internal packages. |
| ☐ | SV-256717r888742_rule | Lookup Service must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled. |
| ☐ | SV-256718r888745_rule | Lookup Service must have mappings set for Java servlet pages. |
| ☐ | SV-256719r888748_rule | Lookup Service must not have the Web Distributed Authoring (WebDAV) servlet installed. |
| ☐ | SV-256720r888751_rule | Lookup Service must be configured with memory leak protection. |
| ☐ | SV-256721r888754_rule | Lookup Service must not have any symbolic links in the web content directory tree. |
| ☐ | SV-256722r888757_rule | Lookup Service directory tree must have permissions in an out-of-the-box state. |
| ☐ | SV-256723r888760_rule | Lookup Service must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-256724r888763_rule | Lookup Service must limit the number of allowed connections. |
| ☐ | SV-256725r888766_rule | Lookup Service must set URIEncoding to UTF-8. |
| ☐ | SV-256726r888769_rule | Lookup Service must set the welcome-file node to a default web page. |
| ☐ | SV-256727r888772_rule | The Lookup Service must not show directory listings. |
| ☐ | SV-256728r888775_rule | Lookup Service must be configured to hide the server version. |
| ☐ | SV-256729r888778_rule | Lookup Service must be configured to show error pages with minimal information. |
| ☐ | SV-256730r888781_rule | Lookup Service must not enable support for TRACE requests. |
| ☐ | SV-256731r888784_rule | Lookup Service must have the debug option turned off. |
| ☐ | SV-256732r888787_rule | Lookup Service must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server. |
| ☐ | SV-256733r888790_rule | Lookup Service log files must be offloaded to a central log server in real time. |
| ☐ | SV-256734r888793_rule | Lookup Service must be configured with the appropriate ports. |
| ☐ | SV-256735r888796_rule | Lookup Service must disable the shutdown port. |
| ☐ | SV-256736r888799_rule | Lookup Service must set the secure flag for cookies. |