UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Web administration tools must be restricted to the web manager and the web manager’s designees.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2248 WG220 A22 SV-32948r2_rule Medium
Description
All automated information systems are at risk of data loss due to disaster or compromise. Failure to provide adequate protection to the administration tools creates risk of potential theft or damage that may ultimately compromise the mission. Adequate protection ensures that server administration operates with less risk of losses or operations outages. The key web service administrative and configuration tools must be accessible only by the authorized web server administrators. All users granted this authority must be documented and approved by the ISSO. Access to the IIS Manager will be limited to authorized users and administrators.
STIG Date
APACHE 2.2 Server for UNIX Security Technical Implementation Guide 2018-07-06

Details

Check Text ( C-29923r1_chk )
Determine which tool or control file is used to control the configuration of the web server.

If the control of the web server is done via control files, verify who has update access to them. If tools are being used to configure the web server, determine who has access to execute the tools.

If accounts other than the SA, the web manager, or the web manager designees have access to the web administration tool or control files, this is a finding.
Fix Text (F-26807r1_fix)
Restrict access to the web administration tool to only the web manager and the web manager’s designees.