Skip to main content
CUI

Documentation - V-206357

V-206357

Web Server Security Requirements Guide

CAT II

Title

The web server must initiate session logging upon start up.

Description

<VulnDiscussion>An attacker can compromise a web server during the startup process. If logging is not initiated until all the web server processes are started, key information may be missed and not available during a forensic investigation. To assure all logable events are captured, the web server must begin logging once the first web server process is initiated.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mit...

Fix Text (Documentation Requirement)

Configure the web server to capture logable events upon startup.

Documentation Status

Cancel
CUI