SV-54261r3_rule
V-41684
SRG-APP-000131-WSR-000073
SRG-APP-000131-WSR-000073
CAT II
10
Configure the web server to enforce, internally or through an external utility, the review, testing and signing of modules before implementation into the production environment.
Review the web server documentation and configuration to determine if web server modules are fully tested before implementation in the production environment.
Review the web server for modules identified as test, debug, or backup and that cannot be reached through the hosted application.
Review the web server to see if the web server or an external utility is in use to enforce the signing of modules before they are put into a production environment.
If development and testing is taking place on the production web server or modules are put into production without being signed, this is a finding.
V-41684
False
SRG-APP-000131-WSR-000073
Review the web server documentation and configuration to determine if web server modules are fully tested before implementation in the production environment.
Review the web server for modules identified as test, debug, or backup and that cannot be reached through the hosted application.
Review the web server to see if the web server or an external utility is in use to enforce the signing of modules before they are put into a production environment.
If development and testing is taking place on the production web server or modules are put into production without being signed, this is a finding.
M
2557