STIGQter STIGQter: STIG Summary: VMware vRealize Automation 7.x Lighttpd Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Sep 2018:

Lighttpd expansion modules must be verified for their integrity before being added to a production web server.

DISA Rule

SV-99905r1_rule

Vulnerability Number

V-89255

Group Title

SRG-APP-000131-WSR-000073

Rule Version

VRAU-LI-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review, test, and sign expansion modules before being implemented into the production environment.

Check Contents

Obtain supporting documentation from the ISSO.

Determine whether expansion modules are being fully reviewed, tested, and signed before being implemented into the production environment.

If the expansion modules are not being fully reviewed, tested, and signed before being implemented into the production environment, this is a finding.

Vulnerability Number

V-89255

Documentable

False

Rule Version

VRAU-LI-000150

Severity Override Guidance

Obtain supporting documentation from the ISSO.

Determine whether expansion modules are being fully reviewed, tested, and signed before being implemented into the production environment.

If the expansion modules are not being fully reviewed, tested, and signed before being implemented into the production environment, this is a finding.

Check Content Reference

M

Target Key

3457

Comments