Check: WG240 W22
APACHE 2.2 Site for Windows STIG:
WG240 W22
(in versions v1 r13 through v1 r10)
Title
Logs of web server access and errors must be established and maintained. (Cat II impact)
Discussion
A major tool in exploring the web site use, attempted use, unusual conditions, and problems are reported in the access and error logs. In the event of a security incident, these logs can provide the SA and the web manager with valuable information. Without these log files, SAs and web managers are seriously hindered in their efforts to respond appropriately to suspicious or criminal actions targeted at the web site.
Check Content
Open a command prompt window. Navigate to the “bin” directory (in many cases this may be [Drive Letter]:\[directory path]\Apache Software Foundation\Apache2.2\bin>). Enter the following command and press Enter: httpd –M This will provide a list of all loaded modules. If the following module is not found this is a finding: log_config_module.
Fix Text
Load log_config_module.
Additional Identifiers
Rule ID: SV-33132r1_rule
Vulnerability ID: V-2250
Group Title: WG240
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |