首页> 美国政府科技报告 >Web Server. Security Technical Implementation Guide. Version 6, Release 1.
【24h】

Web Server. Security Technical Implementation Guide. Version 6, Release 1.

机译:网络服务器。安全技术实施指南。版本6,版本1。

获取原文

摘要

Web servers provide access to data intended for a remote audience. This data may be intended for a restricted audience or it may be releasable to the general public. The web server must be capable of protecting the restricted data, as well as protecting data intended for a general audience. Immediate risks inherent to this role are external attack and accidental exposure. Although security controls such as firewalls, Intrusion Detection Systems (IDSs), and baseline integrity checking tools offer some defense against malicious activity, security for web servers is best achieved through a comprehensive defense-in-depth strategy. This strategy includes, but is not limited to, server configuration to prevent system compromise, operational procedures for posting data to avoid accidental exposure, proper placement of the server within the network infrastructure, and the allowance or denial of ports, protocols, and services used to access the web server. The purpose of this STIG is to assist Department of Defense (DoD) sites in planning web server deployment and securing already-deployed web servers in an effort to achieve the minimum requirements, standards, controls, and options for secure web server operations.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号