SRG-APP-000435 Controls

STIG IDVersionTitleProduct
SRG-APP-000435-API-000995V1R1The API must use a gateway.Security Requirements Guide - API
SRG-APP-000435-CTR-001070V2R4The container platform must protect against or limit the effects of all types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.Security Requirements Guide - Container Platform
SRG-APP-000435-DNS-000084V4R2NSEC3 must be used for all internal DNS zones.Security Requirements Guide - Domain Name Service
SRG-APP-000435-DNS-000087V4R2All authoritative name servers for a zone must be located on different network segments.Security Requirements Guide - Domain Name Service
SRG-APP-000435-DNS-000027V4R2All authoritative name servers for a zone must be geographically disbursed.Security Requirements Guide - Domain Name Service
SRG-APP-000435-DNS-000047V4R2The DNS implementation must prohibit recursion on authoritative name servers.Security Requirements Guide - Domain Name Service
SRG-APP-000435-WSR-000147V4R4The web server must be protected from being stopped by a non-privileged user.Security Requirements Guide - Web Server
SRG-APP-000435-WSR-000148V4R4The web server must be tuned to handle the operational requirements of the hosted application.Security Requirements Guide - Web Server