SV-102655r1_rule
V-92567
SRG-APP-000340-WSR-000029
AS24-W2-000690
CAT II
10
Restrict access to the web administration tool to only the SA, Web Manager, or the Web Manager designees.
Determine which tool or control file is used to control the configuration of the web server.
If the control of the web server is done via control files, verify who has update access to them. If tools are being used to configure the web server, determine who has access to execute the tools.
If accounts other than the System Administrator (SA), the Web Manager, or the Web Manager designees have access to the web administration tool or control files, this is a finding.
V-92567
False
AS24-W2-000690
Determine which tool or control file is used to control the configuration of the web server.
If the control of the web server is done via control files, verify who has update access to them. If tools are being used to configure the web server, determine who has access to execute the tools.
If accounts other than the System Administrator (SA), the Web Manager, or the Web Manager designees have access to the web administration tool or control files, this is a finding.
M
3419