V-206404
SV-206404r961122_rule
CAT II
The web server must augment re-creation to a stable and known baseline.
From: Web Server Security Requirements Guide (V4R4)
Description
<VulnDiscussion>Making certain that the web server has not been updated by an unauthorized user is always a concern. Adding patches, functions, and modules that are untested and not part of the baseline opens the possibility for security risks. The web server must offer, and not hinder, a method that allows for the quick and easy reinstallation of a verified and patched baseline to guarantee the production web server is up-to-date and has not been modified to add functionality or expose security risks.
When the web server does not offer a method to roll back to a clean baseline, external methods, such as a baseline snapshot or virtualizing the web server, can be used.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Review the web server documentation and deployed configuration to determine if the web server offers the capability to reinstall from a known state.
If the web server does not offer this capability, determine if the web server, in any manner, prohibits the reinstallation of a known state.
If the web server does prohibit the reinstallation to a known state, this is a finding.
Fix Text
Configure the web server to augment and not hinder the reinstallation of a known and stable baseline.
CCI Reference
CCI-001190- Created
- 2026-04-07 20:08:40
- Last Updated
- 2026-04-07 20:08:40