| Checked | Name | Title |
|---|---|---|
| ☐ | SV-256611r888324_rule | Performance Charts must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-256612r888327_rule | Performance Charts must limit the number of concurrent connections permitted. |
| ☐ | SV-256613r888330_rule | Performance Charts must limit the maximum size of a POST request. |
| ☐ | SV-256614r888333_rule | Performance Charts must protect cookies from cross-site scripting (XSS). |
| ☐ | SV-256615r888336_rule | Performance Charts must record user access in a format that enables monitoring of remote access. |
| ☐ | SV-256616r888339_rule | Performance Charts must generate log records for system startup and shutdown. |
| ☐ | SV-256617r888342_rule | Performance Charts log files must only be modifiable by privileged users. |
| ☐ | SV-256618r888345_rule | Performance Charts application files must be verified for their integrity. |
| ☐ | SV-256619r888348_rule | Performance Charts must only run one webapp. |
| ☐ | SV-256620r888351_rule | Performance Charts must not be configured with unsupported realms. |
| ☐ | SV-256621r888354_rule | Performance Charts must be configured to limit access to internal packages. |
| ☐ | SV-256622r888357_rule | Performance Charts must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled. |
| ☐ | SV-256623r888360_rule | Performance Charts must have mappings set for Java servlet pages. |
| ☐ | SV-256624r888363_rule | Performance Charts must not have the Web Distributed Authoring (WebDAV) servlet installed. |
| ☐ | SV-256625r888366_rule | Performance Charts must be configured with memory leak protection. |
| ☐ | SV-256626r888369_rule | Performance Charts must not have any symbolic links in the web content directory tree. |
| ☐ | SV-256627r888372_rule | Performance Charts directory tree must have permissions in an out-of-the-box state. |
| ☐ | SV-256628r888375_rule | Performance Charts must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-256629r888378_rule | Performance Charts must limit the number of allowed connections. |
| ☐ | SV-256630r888381_rule | Performance Charts must set "URIEncoding" to UTF-8. |
| ☐ | SV-256631r888384_rule | Performance Charts must use the "setCharacterEncodingFilter" filter. |
| ☐ | SV-256632r888387_rule | Performance Charts must set the welcome-file node to a default web page. |
| ☐ | SV-256633r888390_rule | Performance Charts must not show directory listings. |
| ☐ | SV-256634r888393_rule | Performance Charts must be configured to show error pages with minimal information. |
| ☐ | SV-256635r888396_rule | Performance Charts must be configured to not show error reports. |
| ☐ | SV-256636r888399_rule | Performance Charts must hide the server version. |
| ☐ | SV-256637r888402_rule | Performance Charts must not enable support for TRACE requests. |
| ☐ | SV-256638r888405_rule | Performance Charts must have the debug option turned off. |
| ☐ | SV-256639r888408_rule | Performance Charts must properly configure log sizes and rotation. |
| ☐ | SV-256640r888411_rule | Rsyslog must be configured to monitor and ship Performance Charts log files. |
| ☐ | SV-256641r888414_rule | Performance Charts must be configured with the appropriate ports. |
| ☐ | SV-256642r888417_rule | Performance Charts must disable the shutdown port. |
| ☐ | SV-256643r888420_rule | Performance Charts must set the secure flag for cookies. |
| ☐ | SV-256644r888423_rule | Performance Charts default servlet must be set to "readonly". |