WG220 W22 - Web administration tools must be restricted to the web manager and the web manager's designees.

Information

All automated information systems are at risk of data loss due to disaster or compromise. Failure to provide adequate protection to the administration tools creates risk of potential theft or damage that may ultimately compromise the mission. Adequate protection ensures that server administration operates with less risk of losses or operations outages. The key web service administrative and configuration tools must be accessible only by the authorized web server administrators. All users granted this authority must be documented and approved by the ISSO. Access to the IIS Manager will be limited to authorized users and administrators.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Restrict access to the httpd.conf and supporting .conf files to only the documented SA, web manager, or web manager designees.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R13_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, Rule-ID|SV-33072r4_rule, STIG-ID|WG220_W22, Vuln-ID|V-2248

Plugin: Windows

Control ID: 9fed37ed0721acb5235d3236895c4d6d5942c1673e15cd705e98879a425966fb