27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

immediately after the installati<strong>on</strong> process c<strong>on</strong>cludes. <strong>Securing</strong> the <strong>Web</strong> server applicati<strong>on</strong> would<br />

generally include the following steps:<br />

Patch and upgrade the <strong>Web</strong> server applicati<strong>on</strong><br />

Remove or disable unnecessary services, applicati<strong>on</strong>s, and sample c<strong>on</strong>tent<br />

C<strong>on</strong>figure <strong>Web</strong> server user authenticati<strong>on</strong> and access c<strong>on</strong>trols<br />

C<strong>on</strong>figure <strong>Web</strong> server resource c<strong>on</strong>trols<br />

Test the security of the <strong>Web</strong> server applicati<strong>on</strong> and <strong>Web</strong> c<strong>on</strong>tent.<br />

Organizati<strong>on</strong>s should take steps to ensure that <strong>on</strong>ly appropriate c<strong>on</strong>tent is published <strong>on</strong> a <strong>Web</strong> site.<br />

Many agencies lack a <strong>Web</strong> publishing process or policy that determines what type of informati<strong>on</strong> to<br />

publish openly, what informati<strong>on</strong> to publish with restricted access, and what informati<strong>on</strong> should not be<br />

published to any publicly accessible repository. This is unfortunate because <strong>Web</strong> sites are often <strong>on</strong>e of<br />

the first places that malicious entities search for valuable informati<strong>on</strong>. Some generally accepted examples<br />

of what should not be published or at least should be carefully examined and reviewed before publicati<strong>on</strong><br />

<strong>on</strong> a public <strong>Web</strong> site include—<br />

Classified or proprietary informati<strong>on</strong><br />

Informati<strong>on</strong> <strong>on</strong> the compositi<strong>on</strong> or preparati<strong>on</strong> of hazardous materials or toxins 2<br />

Sensitive informati<strong>on</strong> relating to homeland security<br />

Medical records<br />

An organizati<strong>on</strong>’s detailed physical and informati<strong>on</strong> security safeguards<br />

Details about an organizati<strong>on</strong>’s network and informati<strong>on</strong> system infrastructure (e.g., address ranges,<br />

naming c<strong>on</strong>venti<strong>on</strong>s, access numbers)<br />

Informati<strong>on</strong> that specifies or implies physical security vulnerabilities<br />

Detailed plans, maps, diagrams, aerial photographs, and architectural drawings of organizati<strong>on</strong>al<br />

buildings, properties, or installati<strong>on</strong>s<br />

Any sensitive informati<strong>on</strong> about individuals, such as pers<strong>on</strong>ally identifiable informati<strong>on</strong> (PII), that<br />

might be subject to either Federal, state or, in some instances, internati<strong>on</strong>al privacy laws. 3<br />

Organizati<strong>on</strong>s should ensure appropriate steps are taken to protect <strong>Web</strong> c<strong>on</strong>tent from<br />

unauthorized access or modificati<strong>on</strong>.<br />

2<br />

3<br />

For more guidance <strong>on</strong> protecting this type of informati<strong>on</strong>, see the White House Memorandum dated March 19, 2000, Acti<strong>on</strong><br />

to Safeguard Informati<strong>on</strong> Regarding Weap<strong>on</strong>s of Mass Destructi<strong>on</strong> and Other Sensitive Documents Related to Homeland<br />

Security (http://www.usdoj.gov/oip/foiapost/2002foiapost10.htm).<br />

For more guidance <strong>on</strong> protecting this type of informati<strong>on</strong>, see OMB Memorandum M-06-16 and OMB Memorandum M-07-<br />

16 at http://www.whitehouse.gov/omb/memoranda/.<br />

ES-4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!