SRG-APP-000266 Controls

STIG IDVersionTitleProduct
SRG-APP-000266-API-000535V1R1The API must not disclose sensitive data in error messages.Security Requirements Guide - API
SRG-APP-000266-CTR-000625V2R4The container platform must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.Security Requirements Guide - Container Platform
SRG-APP-000266-MFP-000334V3R4The Mainframe Product must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.Security Requirements Guide - Mainframe Product
SRG-APP-000266-WSR-000142V4R4The web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.Security Requirements Guide - Web Server
SRG-APP-000266-WSR-000159V4R4Warning and error messages displayed to clients must be modified to minimize the identity of the web server, patches, loaded modules, and directory paths.Security Requirements Guide - Web Server
SRG-APP-000266-WSR-000160V4R4Debugging and trace information used to diagnose the web server must be disabled.Security Requirements Guide - Web Server