WA030 - Web content is not reviewed and approved by proper authorities prior to posting to a production web server.

Information

Vulnerability Key: V0002239
IA Controls: DCPR-1 CM Process
Categories: 12.9 Documentation
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
The organization or activity that sponsors the web site will have web content responsibility. These persons
will ensure that all information is kept current and that information and scripting placed on the web server is
reviewed and approved by a configuration management authority. The organization or activity that sponsors
the web site will have web content responsibility. These persons will ensure that all information is kept
current and that information and scripting placed on the web server is reviewed and approved by a
configuration management authority and as needed by the Public Affairs Officer (PAO). Likewise, the
reviewer should verify that local policies have been developed to ensure that all information has been
reviewed and approved for posting by the originating organization according to the DoD Web Site
Administration Policies & Procedures, 25 November 1998 (updated 11 January 2002) available at
http://www.defenselink.mil/webmasters/policy/dod_web_policy_12071998_with_amendments_and_correctio
November 1998.
NOTE: Nessus did not perform this check as it requires manual verification of local policies to ensure content is reviewed by
proper authorities before being posted to production servers.