SV-32951r1_rule
V-2257
WA120
WA120 A22
CAT III
10
Document the administrative users and groups which have access rights to the web server in the web site SOP or in an equivalent document.
Proposed Questions:
How many user accounts are associated with the Web server operation and maintenance?
Where are these accounts documented?
Use the command line utility more /etc/passwd to identify the accounts on the web server.
Query the SA or Web Manager regarding the use of each account and each group.
If the documentation does not match the users and groups found on the server, this is a finding.
V-2257
False
WA120 A22
Proposed Questions:
How many user accounts are associated with the Web server operation and maintenance?
Where are these accounts documented?
Use the command line utility more /etc/passwd to identify the accounts on the web server.
Query the SA or Web Manager regarding the use of each account and each group.
If the documentation does not match the users and groups found on the server, this is a finding.
M
Web Administrator
158