Check: WA155 IIS6
IIS6 Server:
WA155 IIS6
(in version v6 r16)
Title
Classified web servers must be afforded physical security commensurate with the classification of its content. (Cat I impact)
Discussion
When data of a classified nature is migrated to a web server, fundamental principles applicable to the safeguarding of classified material must be followed. A classified web server needs to be afforded physical security commensurate with the classification of its content to ensure the protection of the data it houses.
Check Content
Interview the ISSO, the SA, the Web Administrator, or developers as necessary to determine if a classified web server is afforded physical security commensurate with the classification of its content (i.e., is located in a vault or a room approved for classified storage at the highest classification processed on that system). Ask what the classification of the web server is, and based on the classification, evaluate the location of the web server. Determine if it is approved for storage of that classification level. If there is a traditional reviewer available, work with them to address specific conditions or questions. If the web server is not appropriately physically protected based on its classification, this is a finding.
Fix Text
Relocate the web server to a location appropriate to classified devices.
Additional Identifiers
Rule ID: SV-38173r2_rule
Vulnerability ID: V-13591
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |