Web server defense drafted

"Guidelines on Securing Public Web Servers"

Related Links

Tackling one of the prime targets on a network for cyberattacks, the National Institute of Standards and Technology released a draft of its new guidance on securing public Web servers March 1.

The draft special publication is intended for technical personnel, as it contains detailed guidance and checklists on how to configure the Web server itself, as well as the underlying operating system and security products, such as firewalls and intrusion detection systems.

The guide also covers security administration procedures for Web servers, including logging, backup, recovery, testing and remote administration.

In the appendices, the guide outlines the steps to secure the two most commonly used Web servers, the open-source Apache server and Microsoft Corp.'s Internet Information Server.

Comments on the draft are due to Wayne Jansen ([email protected]) by March 28.

Featured

  • People
    2021 Federal 100 Awards

    Announcing the 2021 Federal 100 Award winners

    Meet the women and men being honored for their exceptional contributions to federal IT.

  • Comment
    Diverse Workforce (Image: Shutterstock)

    Who cares if you wear a hoodie or a suit? It’s the mission that matters most

    Responding to Steve Kelman's recent blog post, Alan Thomas shares the inside story on 18F's evolution.

Stay Connected