STIGQter STIGQter: STIG Summary: APACHE 2.2 Site for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

System logging must be enabled.

DISA Rule

SV-33151r2_rule

Vulnerability Number

V-26281

Group Title

WA00615

Rule Version

WA00615 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the httpd.conf file and configure to load the log_config_module. Configure with ErrorLog and CustomLog directives to ensure comprehensive system and access logging.

Check Contents

Locate the Apache httpd.conf file.

If unable to locate the file, perform a search of the system to find the location of the file.
Open the httpd.conf file with an editor such as Notepad, and search for the following uncommented directives:
LoadModule log_config_module modules/mod_log_config.so
If the LoadModule log_config_module directive is commented out or does not exist, this is a finding.

Search for both of the following uncommented directives: ErrorLog and CustomLog.
If no uncommented directives for both ErrorLog and CustomLog are found, this is a finding.
Note: This check is applicable to every host and virtual host the web server is supporting.

Vulnerability Number

V-26281

Documentable

False

Rule Version

WA00615 W22

Severity Override Guidance

Locate the Apache httpd.conf file.

If unable to locate the file, perform a search of the system to find the location of the file.
Open the httpd.conf file with an editor such as Notepad, and search for the following uncommented directives:
LoadModule log_config_module modules/mod_log_config.so
If the LoadModule log_config_module directive is commented out or does not exist, this is a finding.

Search for both of the following uncommented directives: ErrorLog and CustomLog.
If no uncommented directives for both ErrorLog and CustomLog are found, this is a finding.
Note: This check is applicable to every host and virtual host the web server is supporting.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

161

Comments