| Checked | Name | Title |
|---|---|---|
| ☐ | SV-256745r889205_rule | The Security Token Service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-256746r889208_rule | The Security Token Service must limit the number of concurrent connections permitted. |
| ☐ | SV-256747r889211_rule | The Security Token Service must limit the maximum size of a POST request. |
| ☐ | SV-256748r889214_rule | The Security Token Service must protect cookies from cross-site scripting (XSS). |
| ☐ | SV-256749r889217_rule | The Security Token Service must record user access in a format that enables monitoring of remote access. |
| ☐ | SV-256750r918974_rule | The Security Token Service must generate log records during Java startup and shutdown. |
| ☐ | SV-256751r889223_rule | Security Token Service log files must only be modifiable by privileged users. |
| ☐ | SV-256752r889226_rule | The Security Token Service application files must be verified for their integrity. |
| ☐ | SV-256753r889229_rule | The Security Token Service must only run one webapp. |
| ☐ | SV-256754r889232_rule | The Security Token Service must not be configured with unused realms. |
| ☐ | SV-256755r889235_rule | The Security Token Service must be configured to limit access to internal packages. |
| ☐ | SV-256756r889238_rule | The Security Token Service must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled. |
| ☐ | SV-256757r889241_rule | The Security Token Service must have mappings set for Java servlet pages. |
| ☐ | SV-256758r889244_rule | The Security Token Service must not have the Web Distributed Authoring (WebDAV) servlet installed. |
| ☐ | SV-256759r889247_rule | The Security Token Service must be configured with memory leak protection. |
| ☐ | SV-256760r889250_rule | The Security Token Service must not have any symbolic links in the web content directory tree. |
| ☐ | SV-256761r889253_rule | The Security Token Service directory tree must have permissions in an out-of-the-box state. |
| ☐ | SV-256762r889256_rule | The Security Token Service must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-256763r889259_rule | The Security Token Service must limit the number of allowed connections. |
| ☐ | SV-256764r889262_rule | The Security Token Service must set "URIEncoding" to UTF-8. |
| ☐ | SV-256765r889265_rule | The Security Token Service must use the "setCharacterEncodingFilter" filter. |
| ☐ | SV-256766r889268_rule | The Security Token Service must set the welcome-file node to a default web page. |
| ☐ | SV-256767r889271_rule | The Security Token Service must not show directory listings. |
| ☐ | SV-256768r889274_rule | The Security Token Service must be configured to not show error reports. |
| ☐ | SV-256769r889277_rule | The Security Token Service must not enable support for TRACE requests. |
| ☐ | SV-256770r918976_rule | The Security Token Service must have the debug option disabled. |
| ☐ | SV-256771r918979_rule | The Security Token Service must be configured with the appropriate ports. |
| ☐ | SV-256772r889286_rule | The Security Token Service must disable the shutdown port. |
| ☐ | SV-256773r889289_rule | The Security Token Service must set the secure flag for cookies. |
| ☐ | SV-256774r889292_rule | The Security Token Service default servlet must be set to "readonly". |
| ☐ | SV-256775r889295_rule | Security Token Service log data and records must be backed up onto a different system or media. |