STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

The web server must provide install options to exclude installation of utility programs, services, plug-ins, and modules not necessary for operation.

DISA Rule

SV-54275r3_rule

Vulnerability Number

V-41698

Group Title

SRG-APP-000141-WSR-000080

Rule Version

SRG-APP-000141-WSR-000080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use the web server uninstall facility or manually remove any utility programs, services, or modules not needed by the web server for operation.

Check Contents

Review the web server documentation and deployment configuration to determine which web server utilities, services, and modules are installed. Verify these options are essential to the operation of the web server. Also, confirm the web server install process offers an option to exclude these utilities, services, and modules from installation that are not needed for operation and that there is an uninstall option for their removal.

If there are more utilities, services, or modules installed than are needed for the operation of the web server or the web server does not provide an install facility to customize installation, this is a finding.

Vulnerability Number

V-41698

Documentable

False

Rule Version

SRG-APP-000141-WSR-000080

Severity Override Guidance

Review the web server documentation and deployment configuration to determine which web server utilities, services, and modules are installed. Verify these options are essential to the operation of the web server. Also, confirm the web server install process offers an option to exclude these utilities, services, and modules from installation that are not needed for operation and that there is an uninstall option for their removal.

If there are more utilities, services, or modules installed than are needed for the operation of the web server or the web server does not provide an install facility to customize installation, this is a finding.

Check Content Reference

M

Target Key

2557

Comments