Skip to main content
CUI

Documentation - V-206369

V-206369

Web Server Security Requirements Guide

CAT II

Title

The log information from the web server must be protected from unauthorized modification.

Description

<VulnDiscussion>Log data is essential in the investigation of events. The accuracy of the information is always pertinent. Information that is not accurate does not help in the revealing of potential security risks and may hinder the early discovery of a system compromise. One of the first steps an attacker will undertake is the modification or deletion of log records to cover his tracks and prolong discovery. The web server must protect the log data from unauthorized modification. This can be ...

Fix Text (Documentation Requirement)

Configure the web server log files so unauthorized modification of log information is not possible.

Documentation Status

Cancel
CUI