UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The service account used to run the web service must have its password changed at least annually.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2235 WG060 W22 SV-36489r1_rule IAIA-1 IAIA-2 Medium
Description
Normally, a service account is established for the web service to run under rather than permitting it to run as part of the local system. The password on such accounts must be changed at least annually. If the password is not changed periodically, the potential for a malicious party to gain access to the web services account is greatly enhanced.
STIG Date
APACHE SERVER 2.2 for Windows 2014-04-03

Details

Check Text ( C-33732r1_chk )
Query the IAO and confirm with the SA, the Web Manager, or the individual in an equivalent role.

Proposed Questions:

What is your policy for service account passwords?
What types of services does this policy apply to?
How often is service account passwords changed?

If the web services password is not changed at least annually, this is a finding.
Fix Text (F-29367r1_fix)
Ensure that the service account ID used to run the web site has its password changed at least annually.