6.5 Ensure ASE server names do not disclose sensitive information

Information

When naming ASE server instances, ensure that no reference is made to version numbers
or other sensitive information.

Rationale:

Version or other sensitive information in the server name makes it easier for an attacker to
develop an attack strategy against the server.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. When configuring ASE instances, follow a naming convention that does not include
version numbers or other sensitive information.

See Also

https://workbench.cisecurity.org/files/1612