Interview the IAO, the SA, the web administrator, or developers as necessary to determine if a classified web server is afforded physical security commensurate with the classification of its content (i.e., is located in a vault or a room approved for classified storage at the highest classification processed on that system).
Ask what the classification of the web server is. Based on the classification, evaluate the location of the web server to determine if it is approved for storage of that classification level.
If there is a traditional reviewer available, work with him/her to address specific conditions or questions.
If the web server is not appropriately physically protected based on its classification, this is a finding. |