27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

Completed<br />

Acti<strong>on</strong><br />

C<strong>on</strong>duct remote administrati<strong>on</strong> and c<strong>on</strong>tent updates<br />

Use a str<strong>on</strong>g authenticati<strong>on</strong> mechanism (e.g., public/private key pair, two-factor<br />

authenticati<strong>on</strong>)<br />

Restrict hosts that can be used to remotely administer or update c<strong>on</strong>tent <strong>on</strong> the<br />

<strong>Web</strong> server by IP address and to the internal network<br />

Use secure protocols (e.g., SSH, HTTPS)<br />

Enforce the c<strong>on</strong>cept of least privilege <strong>on</strong> remote administrati<strong>on</strong> and c<strong>on</strong>tent<br />

updating (e.g., attempt to minimize the access rights for the remote<br />

administrati<strong>on</strong>/update accounts)<br />

Change any default accounts or passwords from the remote administrati<strong>on</strong> utility<br />

or applicati<strong>on</strong><br />

Do not allow remote administrati<strong>on</strong> from the Internet unless mechanisms such as<br />

VPNs are used<br />

Do not mount any file shares <strong>on</strong> the internal network from the <strong>Web</strong> server or vice<br />

versa<br />

9-15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!