STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

The service account used to run the web service must have its password changed at least annually.

DISA Rule

SV-36489r4_rule

Vulnerability Number

V-2235

Group Title

WG060

Rule Version

WG060 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that the service account IDs used to run the web server and sites are documented and have their passwords changed at least annually.

Check Contents

Interview the ISSO and confirm with the SA, the Web Manager, or the individual in an equivalent role. Ask for the web server’s documented procedures and processes.

Verify the documented procedures and processes identify web server related service accounts, which services are related to web server operations and include a policy requiring service account passwords to be change at least annually.
If the documented procedures and processes do not identify web server related service accounts, which services are related to web server operations and include a policy requiring service account passwords to be change at least annually, this is a finding.

Vulnerability Number

V-2235

Documentable

False

Rule Version

WG060 W22

Severity Override Guidance

Interview the ISSO and confirm with the SA, the Web Manager, or the individual in an equivalent role. Ask for the web server’s documented procedures and processes.

Verify the documented procedures and processes identify web server related service accounts, which services are related to web server operations and include a policy requiring service account passwords to be change at least annually.
If the documented procedures and processes do not identify web server related service accounts, which services are related to web server operations and include a policy requiring service account passwords to be change at least annually, this is a finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments