Warning! Audit Deprecated
Information
Vulnerability Key: V0002232
IA Controls: IAAC-1 Account Control
Categories: 1.1 Passwords, 1.1 Documentation and Storage
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.6, Web Site Administration Policies & Procedures, With
Amendments and Corrections incorporated in red italics.
Normally, a service account is established for the web server. This is because a privileged account
is not desirable and the server is designed to run for long uninterrupted periods of time. The SA or
Web Manager will need password access to the web server to restart the service in the event of an
emergency as the web server is not to restart automatically after an unscheduled interruption.
Where possible, the account used to run the web server should be a non-privileged account.
Review the list of account user names listed for each application to ensure they are non-privileged accounts.