SV-32957r1_rule
V-2234
WG040
WG040 A22
CAT II
10
Configure the public web server to not have a trusted relationship with any system resource that is also not accessible to the public. Web content is not to be shared via Microsoft shares or NFS mounts.
Determine whether the public web server has a two-way trusted relationship with any private asset located within the network. Private web server resources (e.g., drives, folders, printers, etc.) will not be directly mapped to or shared with public web servers.
If sharing is selected for any web folder, this is a finding.
The following checks indicate inappropriate sharing of private resources with the public web server:
If private resources (e.g., drives, partitions, folders/directories, printers, etc.) are shared with the public web server, then this is a finding.
V-2234
False
WG040 A22
Determine whether the public web server has a two-way trusted relationship with any private asset located within the network. Private web server resources (e.g., drives, folders, printers, etc.) will not be directly mapped to or shared with public web servers.
If sharing is selected for any web folder, this is a finding.
The following checks indicate inappropriate sharing of private resources with the public web server:
If private resources (e.g., drives, partitions, folders/directories, printers, etc.) are shared with the public web server, then this is a finding.
M
Web Administrator
158