<?xml version='1.0' encoding='UTF-8'?>
<cce:cce_list xmlns='http://cce.mitre.org' xmlns:cce='http://cce.mitre.org' xmlns:dcterms='http://purl.org/dc/terms/' version='5.20130214' modified='2013-02-11'>
  <cces modified='2013-02-11'>
    <cce cce_id='CCE-5847-9' platform='aix5.3' modified='2009-04-30'>
      <description>/export/home should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5424-7' platform='aix5.3' modified='2009-04-30'>
      <description>/var should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5710-9' platform='aix5.3' modified='2009-04-30'>
      <description>/opt should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5662-2' platform='aix5.3' modified='2009-04-30'>
      <description>The shell for the root account should be located on the appropriate filesystem</description>
      <parameters>
        <parameter>filesystem</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5317-3' platform='aix5.3' modified='2009-04-30'>
      <description>Core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5384-3' platform='aix5.3' modified='2009-04-30'>
      <description>The read-only SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5723-2' platform='aix5.3' modified='2009-04-30'>
      <description>The read/write SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5634-1' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should ban or allow usernames or UIDs in passwords as appropriate</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5352-0' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should ban or allow words found in a dictionary as appropriate.</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5848-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should enforce the correct amount of special characters</description>
      <parameters>
        <parameter>number of special characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5443-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should enforce or not enforce the requirement to have mixed case passwords as appropriate.</description>
      <parameters>
        <parameter>enforce/not enforce</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5664-8' platform='aix5.3' modified='2009-04-30'>
      <description>The minimum password age should be set as appropriate</description>
      <parameters>
        <parameter>number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5804-0' platform='aix5.3' modified='2009-04-30'>
      <description>The minimum required password length should be set as appropriate</description>
      <parameters>
        <parameter>number of characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4858-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password history should be saved for an appropriate number of password changes</description>
      <parameters>
        <parameter>number of password changes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5775-2' platform='aix5.3' modified='2009-04-30'>
      <description>The number of consecutive failed login attempts required to trigger a lockout should be set as appropriate</description>
      <parameters>
        <parameter>number of consecutive failed login attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5761-2' platform='aix5.3' modified='2009-04-30'>
      <description>Login access to accounts without passwords should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/shadow</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5841-2' platform='aix5.3' modified='2009-04-30'>
      <description>New users should be required or not required to change their password on first login as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5858-6' platform='aix5.3' modified='2009-04-30'>
      <description>Access to single-user mode (maintainence mode) should require the root password or not as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5078-1' platform='aix5.3' modified='2009-04-30'>
      <description>The delay between failed logins should be set as appropriate</description>
      <parameters>
        <parameter>number of seconds</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5715-8' platform='aix5.3' modified='2009-04-30'>
      <description>All files should be owned by an existing account or not as appropriate.</description>
      <parameters>
        <parameter>existing account required / existing account not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5684-6' platform='aix5.3' modified='2009-04-30'>
      <description>All files should be owned by an existing group or not as appropriate.</description>
      <parameters>
        <parameter>existing group required / existing group not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5244-9' platform='aix5.3' modified='2009-04-30'>
      <description>The console login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/login.cfg</technical_mechanism>
        <technical_mechanism>via /etc/motd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5402-3' platform='aix5.3' modified='2009-04-30'>
      <description>The SSH login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5622-6' platform='aix5.3' modified='2009-04-30'>
      <description>The telnet login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5843-8' platform='aix5.3' modified='2009-04-30'>
      <description>The ftp login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5842-0' platform='aix5.3' modified='2009-04-30'>
      <description>The graphical login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5560-8' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts other than root should be allowed to have the UID 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4873-6' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts other than root and locked system accounts should be allowed to have a GID of 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5187-0' platform='aix5.3' modified='2009-04-30'>
      <description>Each account should be assigned a unique UID or not as appropriate</description>
      <parameters>
        <parameter>unique/not unique</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5765-3' platform='aix5.3' modified='2009-04-30'>
      <description>The ftp account should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4884-3' platform='aix5.3' modified='2009-04-30'>
      <description>Login accounts should include an appropriate GECOS identifier or no GECOS identifier</description>
      <parameters>
        <parameter>GECOS value, null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4.1 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5381-9' platform='aix5.3' modified='2009-04-30'>
      <description>The screen lock should activate after an appropriate period of inactivity</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xscreensaver</technical_mechanism>
        <technical_mechanism>via dtsession</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5645-7' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all shell executables.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5597-0' platform='aix5.3' modified='2009-04-30'>
      <description>Remote (serial) consoles should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via BIOS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5676-2' platform='aix5.3' modified='2009-04-30'>
      <description>Root logins should be restricted to the console or not as appropriate.</description>
      <parameters>
        <parameter>restricted/not restricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/default/login</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5733-1' platform='aix5.3' modified='2009-04-30'>
      <description>.netrc files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5702-6' platform='aix5.3' modified='2009-04-30'>
      <description>.rhosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5076-5' platform='aix5.3' modified='2009-04-30'>
      <description>.shosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5442-9' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/hosts.equiv file should exist or not as appropriate.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5640-8' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/passwd file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4893-4' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/shadow file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5024-5' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/group file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (10)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5742-2' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/shells file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (11)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5777-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shells referenced in /etc/passwd should be included in /etc/shells or not as appropriate</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5605-1' platform='aix5.3' modified='2009-04-30'>
      <description>Groups referenced in /etc/passwd should be included in /etc/group or not as appropriate.</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (15)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5750-5' platform='aix5.3' modified='2009-04-30'>
      <description>The home directory for the root account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (16)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5199-5' platform='aix5.3' modified='2009-04-30'>
      <description>The home directory for each user account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (17)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5310-8' platform='aix5.3' modified='2009-04-30'>
      <description>Home directories referenced in /etc/passwd should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (18)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5327-2' platform='aix5.3' modified='2009-04-30'>
      <description>All device files should be located inside an appropriate directory</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (24)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4900-7' platform='aix5.3' modified='2009-04-30'>
      <description>The ntpd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5675-4' platform='aix5.3' modified='2009-04-30'>
      <description>The Network Time Protocol (ntp) synchronization server should be set appropriately.</description>
      <parameters>
        <parameter>timeserver</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>ntpd.conf</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5147-4' platform='aix5.3' modified='2009-04-30'>
      <description>All logon attempts should be logged or not logged as appropriate</description>
      <parameters>
        <parameter>logged/not logged</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5724-0' platform='aix5.3' modified='2009-04-30'>
      <description>All su (switch user) activity should be logged or not as appropriate</description>
      <parameters>
        <parameter>logged/not logged</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5614-3' platform='aix5.3' modified='2009-04-30'>
      <description>Filesystem logging/journaling should be performed or not as appropriate</description>
      <parameters>
        <parameter>performed/not performed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5834-7' platform='aix5.3' modified='2009-04-30'>
      <description>Automount should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5745-5' platform='aix5.3' modified='2009-04-30'>
      <description>Source-routed packets should be accepted or rejected as appropriate.</description>
      <parameters>
        <parameter>accepted/rejected</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5587-1' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP timestamp requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5525-1' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP timestamp broadcast requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4930-4' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP echo (ping) requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4901-5' platform='aix5.3' modified='2009-04-30'>
      <description>Executable stack should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5017-9' platform='aix5.3' modified='2009-04-30'>
      <description>The default gateway should be set appropriately.</description>
      <parameters>
        <parameter>IP address/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/default/route.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5347-0' platform='aix5.3' modified='2009-04-30'>
      <description>The inetd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5193-8' platform='aix5.3' modified='2009-04-30'>
      <description>echo service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5725-7' platform='aix5.3' modified='2009-04-30'>
      <description>netstat service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5801-6' platform='aix5.3' modified='2009-04-30'>
      <description>rcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5506-1' platform='aix5.3' modified='2009-04-30'>
      <description>chargen service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5791-9' platform='aix5.3' modified='2009-04-30'>
      <description>finger service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5743-0' platform='aix5.3' modified='2009-04-30'>
      <description>tftpd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5773-7' platform='aix5.3' modified='2009-04-30'>
      <description>walld service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5461-9' platform='aix5.3' modified='2009-04-30'>
      <description>rstatd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4905-6' platform='aix5.3' modified='2009-04-30'>
      <description>sprayd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5463-5' platform='aix5.3' modified='2009-04-30'>
      <description>rusersd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5542-6' platform='aix5.3' modified='2009-04-30'>
      <description>rlogin service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5431-2' platform='aix5.3' modified='2009-04-30'>
      <description>rsh service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5780-2' platform='aix5.3' modified='2009-04-30'>
      <description>ftp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5872-7' platform='aix5.3' modified='2009-04-30'>
      <description>telnet service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4909-8' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5343-9' platform='aix5.3' modified='2009-04-30'>
      <description>inn service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5611-9' platform='aix5.3' modified='2009-04-30'>
      <description>uucp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5598-8' platform='aix5.3' modified='2009-04-30'>
      <description>rexec service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5550-9' platform='aix5.3' modified='2009-04-30'>
      <description>inetd logging should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4911-4' platform='aix5.3' modified='2009-04-30'>
      <description>font-service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #20</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4926-2' platform='aix5.3' modified='2009-04-30'>
      <description>imap2 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4913-0' platform='aix5.3' modified='2009-04-30'>
      <description>pop3 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5681-2' platform='aix5.3' modified='2009-04-30'>
      <description>ident service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5368-6' platform='aix5.3' modified='2009-04-30'>
      <description>rexd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5549-1' platform='aix5.3' modified='2009-04-30'>
      <description>daytime service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5144-1' platform='aix5.3' modified='2009-04-30'>
      <description>dtspc (cde-spc) service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5223-3' platform='aix5.3' modified='2009-04-30'>
      <description>rquotad service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #28</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5738-0' platform='aix5.3' modified='2009-04-30'>
      <description>cmsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5456-9' platform='aix5.3' modified='2009-04-30'>
      <description>tooltalk service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4918-9' platform='aix5.3' modified='2009-04-30'>
      <description>xdmcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5798-4' platform='aix5.3' modified='2009-04-30'>
      <description>discard service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4923-9' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5917-0' platform='aix5.3' modified='2009-04-30'>
      <description>vino-server service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4934-6' platform='aix5.3' modified='2009-04-30'>
      <description>The bind service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5535-0' platform='aix5.3' modified='2009-04-30'>
      <description>The version string reported by the bind service should be configured appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/named.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5117-7' platform='aix5.3' modified='2009-04-30'>
      <description>SSH Protocol v1 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/ssh/ssh_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.2 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5690-3' platform='aix5.3' modified='2009-04-30'>
      <description>TCP_WRAPPERS should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5852-9' platform='aix5.3' modified='2009-04-30'>
      <description>SNMP version 1 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5068-2' platform='aix5.3' modified='2009-04-30'>
      <description>The nfsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5569-9' platform='aix5.3' modified='2009-04-30'>
      <description>The mountd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5806-5' platform='aix5.3' modified='2009-04-30'>
      <description>The statd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5882-6' platform='aix5.3' modified='2009-04-30'>
      <description>The lockd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5414-8' platform='aix5.3' modified='2009-04-30'>
      <description>NFS should be configured to respond or not as appropriate to client requests that do not include a user id .</description>
      <parameters>
        <parameter>respond/not respond</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5348-8' platform='aix5.3' modified='2009-04-30'>
      <description>NFS should be configured to respond or not as appropriate to client requests that do not originate from a privileged port.</description>
      <parameters>
        <parameter>respond/not respond</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5511-1' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_NONE authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5480-9' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_UNIX authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4957-7' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_DES authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4958-5' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_KERB authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5922-0' platform='aix5.3' modified='2009-04-30'>
      <description>The read-only (ro) option should be enabled or disabled as appropriate for all NFS exports.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5790-1' platform='aix5.3' modified='2009-04-30'>
      <description>The nosuid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5189-6' platform='aix5.3' modified='2009-04-30'>
      <description>The nosgid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5876-8' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4959-3' platform='aix5.3' modified='2009-04-30'>
      <description>The sendmail banner should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5115-1' platform='aix5.3' modified='2009-04-30'>
      <description>The decode sendmail alias should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/aliases</technical_mechanism>
        <technical_mechanism>via /usr/lib/aliases</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5445-2' platform='aix5.3' modified='2009-04-30'>
      <description>.forward files should be allowed or disallowed as appropriate for all users</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via rm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4960-1' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through the aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5802-4' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through the aliases file should reside a directory with an appropriate user owner</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5212-6' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail vrfy command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5291-0' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail expn command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) h)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5741-4' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail should be configured with an appropriate logging level</description>
      <parameters>
        <parameter>logging level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4967-6' platform='aix5.3' modified='2009-04-30'>
      <description>The sendmail help command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) k)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5783-6' platform='aix5.3' modified='2009-04-30'>
      <description>NIS should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4975-9' platform='aix5.3' modified='2009-04-30'>
      <description>NIS+ server should operate at an appropriate security level</description>
      <parameters>
        <parameter>security level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NIS+</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5138-3' platform='aix5.3' modified='2009-04-30'>
      <description>X-Windows should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
        <technical_mechanism>via /etc/inittab vi RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5711-7' platform='aix5.3' modified='2009-04-30'>
      <description>Authorized X-clients should be listed or not in the X*.hosts file as appropriate</description>
      <parameters>
        <parameter>listed/not listed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/X*.hosts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4984-1' platform='aix5.3' modified='2009-04-30'>
      <description>X-Windows should write .Xauthority files to users' home directories or not as appropriate</description>
      <parameters>
        <parameter>write/not write</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via xdm</technical_mechanism>
        <technical_mechanism>via gdm</technical_mechanism>
        <technical_mechanism>via kdm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5975-8' platform='aix5.3' modified='2009-04-30'>
      <description>X11 forwarding via SSH should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5931-1' platform='aix5.3' modified='2009-04-30'>
      <description>Samba should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4994-0' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'hosts allow' option should be configured with an appropriate set of networks</description>
      <parameters>
        <parameter>list of networks</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5923-8' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'security option' option should be set as appropriate</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5939-4' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'encrypt' passwords option should be set as appropriate</description>
      <parameters>
        <parameter>yes/no</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5891-7' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'smb passwd file' option should be set to an appropriate password file or no password file</description>
      <parameters>
        <parameter>file/nothing</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5234-0' platform='aix5.3' modified='2009-04-30'>
      <description>IPv6 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via SMIT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5767-9' platform='aix5.3' modified='2009-04-30'>
      <description>The "at" utility directory permissions should be set as appropriate</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5846-1' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5991-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5705-9' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directory permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5678-8' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directory permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5942-8' platform='aix5.3' modified='2009-04-30'>
      <description>Cron log file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5770-3' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5280-3' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5896-6' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5474-2' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/kmem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5363-7' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/mem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5566-5' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/null file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5851-1' platform='aix5.3' modified='2009-04-30'>
      <description>resolv.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5821-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5755-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all user home directories.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5807-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5759-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/at file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5979-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/rdist file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5228-2' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/sbin/sync file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5951-9' platform='aix5.3' modified='2009-04-30'>
      <description>Superuser account home directories' permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5981-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5668-9' platform='aix5.3' modified='2009-04-30'>
      <description>smbpassword executable permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5010-4' platform='aix5.3' modified='2009-04-30'>
      <description>Aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5666-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set as appropriate for the log file configured to capture critical sendmail messages.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5012-0' platform='aix5.3' modified='2009-04-30'>
      <description>All files executed through /etc/aliases file entries should have file permissions set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5796-8' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5747-1' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #38</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5849-5' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5893-3' platform='aix5.3' modified='2009-04-30'>
      <description>The /bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #40</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5734-9' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #41</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5862-8' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5954-3' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5027-8' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #44</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5206-8' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5907-1' platform='aix5.3' modified='2009-04-30'>
      <description>The /sbin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #46</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5040-1' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #47</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5049-2' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #48</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5056-7' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #49</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6031-9' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6004-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #51</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5974-1' platform='aix5.3' modified='2009-04-30'>
      <description>The /usr/bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #52</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5863-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #53</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5815-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #54</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5955-0' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #56</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6052-5' platform='aix5.3' modified='2009-04-30'>
      <description>/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #57</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6021-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #58</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5272-0' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #59</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5884-2' platform='aix5.3' modified='2009-04-30'>
      <description>.Xauthority file permissions should be set appropriately for all users.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #60</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6023-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #61</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5349-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/cron.d/at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #62</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6050-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/cron.d/cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #63</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5833-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #64</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5803-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/default/* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #65</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5820-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/default/login file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5397-5' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/ftpusers file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #69</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5226-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/host.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5903-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/hostname* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #71</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5970-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/hosts file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5930-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/inetd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #73</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5698-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/issue file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #75</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5641-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5909-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #77</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5985-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/mail/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5350-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/motd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #79</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5988-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/netconfig file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #80</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5817-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #81</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5231-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/pam.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #82</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5323-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #83</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5526-9' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #84</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5631-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #85</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5728-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #86</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5512-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #87</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5074-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #88</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5808-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #89</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5075-7' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5932-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/fstab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #91</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5825-5' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5279-5' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/loginlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #93</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5984-0' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/messages file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #94</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5656-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/sulog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #95</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5736-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/utmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #96</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6062-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/wtmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #97</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5453-6' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/authlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #98</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6048-3' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/syslog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #99</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5832-1' platform='aix5.3' modified='2009-04-30'>
      <description>/var/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6017-8' platform='aix5.3' modified='2009-04-30'>
      <description>/var/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #101</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5986-5' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/pt_chmod file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #103</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5875-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/embedded_us file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #104</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5977-4' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #105</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5627-5' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/kerberos/bin/rsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #107</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5455-1' platform='aix5.3' modified='2009-04-30'>
      <description>/var/spool/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5077-3' platform='aix5.3' modified='2009-04-30'>
      <description>smbpassword file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #109</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5695-2' platform='aix5.3' modified='2009-04-30'>
      <description>At directory should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5646-5' platform='aix5.3' modified='2009-04-30'>
      <description>At directory should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5161-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5254-8' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5853-7' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5632-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5319-9' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5412-2' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5082-3' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5754-7' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6022-8' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5868-5' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5961-8' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5837-0' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny data should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5929-5' platform='aix5.3' modified='2009-04-30'>
      <description>crontab files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5085-6' platform='aix5.3' modified='2009-04-30'>
      <description>crontab files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5919-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/resolv.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5888-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/resolv.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5941-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.boot file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5910-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.boot file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5822-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5663-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5086-4' platform='aix5.3' modified='2009-04-30'>
      <description>Each user home directory should be owned by an appropriate user.</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6007-9' platform='aix5.3' modified='2009-04-30'>
      <description>Each user home directory should be owned by an appropriate group.</description>
      <parameters>
        <parameter>group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5088-0' platform='aix5.3' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5732-3' platform='aix5.3' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5326-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5296-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5283-7' platform='aix5.3' modified='2009-04-30'>
      <description>Exported files and directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5428-8' platform='aix5.3' modified='2009-04-30'>
      <description>Exported files and directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5626-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5957-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5740-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5090-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6086-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6055-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6024-4' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd executable should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5839-6' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd executable should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5091-4' platform='aix5.3' modified='2009-04-30'>
      <description>aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5497-3' platform='aix5.3' modified='2009-04-30'>
      <description>aliases file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6029-3' platform='aix5.3' modified='2009-04-30'>
      <description>The log file configured to capture critical sendmail messages should be owned by the appropriate user.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5116-9' platform='aix5.3' modified='2009-04-30'>
      <description>The log file configured to capture critical sendmail messages should be owned by the appropriate group.</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5154-0' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through aliases file entries should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6013-7' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through aliases file entries should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5999-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shell files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6003-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shell files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6096-2' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6107-7' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5171-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5688-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5185-4' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5671-3' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5706-7' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6177-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5860-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6146-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5992-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5615-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5580-6' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5191-2' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6088-9' platform='aix5.3' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should or should not contain world-writable files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
        <technical_mechanism>via profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6044-2' platform='aix5.3' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should not contain the current directory as the first or last entry</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5195-3' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by global initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local  init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6012-9' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by local initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5361-1' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5204-3' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by run control scripts as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6087-1' platform='aix5.3' modified='2009-04-30'>
      <description>The system umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6056-6' platform='aix5.3' modified='2009-04-30'>
      <description>The user umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5816-4' platform='aix5.3' modified='2009-04-30'>
      <description>The cron.allow file should be configured with the set of users permitted to use the cron facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5785-1' platform='aix5.3' modified='2009-04-30'>
      <description>The cron.deny file should be configured with the set of users not permitted to use the cron facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5661-4' platform='aix5.3' modified='2009-04-30'>
      <description>Cron logging should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.3 4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5877-6' platform='aix5.3' modified='2009-04-30'>
      <description>The at.allow file should be configured with the set of users permitted to use the at facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5600-2' platform='aix5.3' modified='2009-04-30'>
      <description>The at.deny file should be configured with the set of users not permitted to use the at facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5489-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6066-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6084-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5819-8' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5648-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5205-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5548-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6085-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5926-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5224-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6037-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6011-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5980-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6103-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5945-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6079-8' platform='aix5.3' modified='2009-04-30'>
      <description>The authentication mechanism (SYSTEM attribute) should be set appropriately for each user</description>
      <parameters>
        <parameter>authentication system</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6158-0' platform='aix5.3' modified='2009-04-30'>
      <description>Trusted Computing Base should be installed or not as appropriate</description>
      <parameters>
        <parameter>installed/not installed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.2 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5484-1' platform='aix5.3' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled as appropriate in runcontrol scripts</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/inittab</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5378-5' platform='aix5.3' modified='2009-04-30'>
      <description>BIN mode auditing should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5235-7' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts should be present or absent from the audit config file as appropriate</description>
      <parameters>
        <parameter>present/absent</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5913-9' platform='aix5.3' modified='2009-04-30'>
      <description>System logons should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5993-1' platform='aix5.3' modified='2009-04-30'>
      <description>System logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5693-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password changes should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6230-7' platform='aix5.3' modified='2009-04-30'>
      <description>su usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5697-8' platform='aix5.3' modified='2009-04-30'>
      <description>Creation/modification of superuser groups should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6197-8' platform='aix5.3' modified='2009-04-30'>
      <description>Startup/shutdown of audit functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5889-1' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate revocation should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6109-3' platform='aix5.3' modified='2009-04-30'>
      <description>Remote access from outside the corporate network should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5242-3' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chown command should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6213-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rcp binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5680-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rlogin binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5591-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rlogind binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5543-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rsh binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5934-5' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rshd binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6009-5' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the tftp binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5996-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the tftpd binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6135-8' platform='aix5.3' modified='2009-04-30'>
      <description>Global initialization files should allow or deny write access to the terminal as appropriate</description>
      <parameters>
        <parameter>allow/deny</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.5 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5963-4' platform='aix5.3' modified='2009-04-30'>
      <description>Netrc should be configured with an appropriate set of services</description>
      <parameters>
        <parameter>list of services</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/sysck.cfg</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6104-4' platform='aix5.3' modified='2009-04-30'>
      <description>Change of file ownership should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5324-9' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chmod command should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6170-5' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate creation should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5243-1' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate deletion should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6016-0' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate retrieval should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6174-7' platform='aix5.3' modified='2009-04-30'>
      <description>Startup or shutdown of the audit process should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5245-6' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chgrp should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5253-0' platform='aix5.3' modified='2009-04-30'>
      <description>Use of mkgroup should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6189-5' platform='aix5.3' modified='2009-04-30'>
      <description>Use of rmgroup should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6035-0' platform='aix5.3' modified='2009-04-30'>
      <description>Use of change user functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6100-2' platform='aix5.3' modified='2009-04-30'>
      <description>Terminal logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6157-2' platform='aix5.3' modified='2009-04-30'>
      <description>Exit function usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6156-4' platform='aix5.3' modified='2009-04-30'>
      <description>Hard core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5751-3' platform='aix5.3' modified='2009-04-30'>
      <description>Remote root logins via SSH should be allowed or not as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/ssh/sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27905-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27713-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27582-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27923-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27885-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27991-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27484-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27784-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27505-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27969-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27797-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28018-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27962-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27025-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28008-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27805-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27264-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27863-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27790-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27855-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27823-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27701-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27960-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27939-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27324-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 21. Deny HTTP TRACE Requests with Mod_Rewrite p33</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.11 Restrict HTTP Protocol Version p19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27896-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27739-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27983-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27942-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p13</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27029-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27867-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27951-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27963-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28026-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27321-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27592-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27755-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27958-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27804-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27988-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27832-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27770-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27475-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28028-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27970-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27036-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27136-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27932-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27561-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28004-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 4. ErrorLog - Syslog p70-71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.5 Syslog Logging p44-45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27956-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27929-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27632-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27902-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27997-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27537-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28019-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27874-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27656-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24-25</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27071-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27987-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 16. Limiting HTTP Request Methods p25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27489-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28009-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27977-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27802-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 14. Authentication Mechanisms p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27803-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache Server Administrator email address should be set correctly.</description>
      <parameters>
        <parameter>(1) email address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 'ServerAdmin' line in Apache configuration file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27924-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 5. Lock Down the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28027-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27147-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28109-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27949-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27502-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28001-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28139-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27654-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27916-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27785-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "ExecCGI" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28125-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for all DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Order directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28116-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) TARGET: Directory directive</technical_mechanism>
        <technical_mechanism>(2) Apache configuration file: Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28025-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Action directive shoud be configured appropriately.</description>
      <parameters>
        <parameter>(1) action-type</parameter>
        <parameter>(2) cgi-script</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Action directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: MIME types for csh or sh shell programs must be disabled.
STIG ID: WG370 A22 Rule ID: SV-36309r1_rule Vuln ID: V-2225
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28092-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AddHandler directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) handler-name</parameter>
        <parameter>(2) extension</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AddHandler directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: MIME types for csh or sh shell programs must be disabled.
STIG ID: WG370 A22 Rule ID: SV-36309r1_rule Vuln ID: V-2225
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28000-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with nfs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27251-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with smb should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/samba/smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28090-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 A22  Rule ID: SV-6928r4_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 W22  Rule ID: SV-36644r1_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27660-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apachce "MaxKeepAliveRequests" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxKeepAliveRequests directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 A22  Rule ID: SV-33018r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 W22  Rule ID: SV-33105r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28122-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All readable Apache web document directories should have their default webpage configured appropriately.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directories (from Apache configuration file: DocumentRoot directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 A22  Rule ID: SV-33020r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 W22  Rule ID: SV-33107r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27490-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28118-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27952-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27955-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's log_config_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) log_config_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 A22  Rule ID: SV-33025r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 W20  Rule ID: SV-36668r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27967-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The file permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27906-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27976-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28059-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27888-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27889-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27795-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28071-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27981-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28013-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28141-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28020-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28084-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27611-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28146-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27811-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28107-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27499-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27620-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27933-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28117-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27957-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27871-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27647-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28055-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28119-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28069-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28006-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27742-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27914-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28046-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28126-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27979-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27643-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28035-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27984-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28115-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /cgi-bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28068-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28030-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28044-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache site's robots.txt should be configured to disallow paths and files as appropriate.</description>
      <parameters>
        <parameter>(1) User-Agent</parameter>
        <parameter>(2) Disallowed path(s)|file(s)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) robots.txt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 A22  Rule ID: SV-33028r1_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 W22  Rule ID: SV-28798r2_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28137-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's ssl_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ssl_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28104-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache SSLProtocol directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SSLv2 / SSLv3 / TLSv1 / All</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLProtocol directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27980-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache SSLEngine directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27821-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 A22  Rule ID: SV-36672r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 W22  Rule ID: SV-33098r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27835-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All Apache's online manual should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) manual in the Server Root directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28034-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28010-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 A22  Rule ID: SV-36642r1_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 W22  Rule ID: SV-28654r2_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28143-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 A22  Rule ID: SV-32977r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 W22  Rule ID: SV-32980r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27148-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 A22  Rule ID: SV-32844r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 W22  Rule ID: SV-32987r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27938-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 A22  Rule ID: SV-32877r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 W22  Rule ID: SV-32880r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27479-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf StartServers directive must be set properly.
STIG ID: WA000-WWA026 A22  Rule ID: SV-36645r1_rule  Vuln ID: V-13727
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27989-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MinSpareServers directive must be set properly. 
STIG ID: WA000-WWA028 A22  Rule ID: SV-36646r1_rule  Vuln ID: V-13728
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28133-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxSpareServers directive must be set properly. 
STIG ID: WA000-WWA030 A22  Rule ID: SV-36648r1_rule  Vuln ID: V-13729
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27188-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxClients directive must be set properly. 
STIG ID: WA000-WWA032 A22  Rule ID: SV-36649r1_rule  Vuln ID: V-13730
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28066-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 A22  Rule ID: SV-40129r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28183-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28101-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28100-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 A22  Rule ID: SV-32754r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27737-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 A22  Rule ID: SV-32755r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28089-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 A22  Rule ID: SV-32756r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass+G66</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 W22  Rule ID: SV-33008r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27646-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 A22  Rule ID: SV-32757r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 W22  Rule ID: SV-33009r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27907-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 A22  Rule ID: SV-32766r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 W22  Rule ID: SV-33010r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28106-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 A22  Rule ID: SV-32768r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 W22  Rule ID: SV-33011r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27847-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 4. ErrorLog - Syslog p70-71</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 A22  Rule ID: SV-33192r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 W22  Rule ID: SV-33147r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27798-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 A22  Rule ID: SV-33206r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 W22  Rule ID: SV-33151r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27814-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 A22  Rule ID: SV-33207r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 W22  Rule ID: SV-33153r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27207-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W20  Rule ID: SV-36611r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27946-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_fs_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_fs_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W20  Rule ID: SV-36611r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28200-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's info_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) info_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W20  Rule ID: SV-36612r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27789-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's status_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) status_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W20  Rule ID: SV-36612r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28182-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28075-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_ftp_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_ftp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27846-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_http_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_http_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28067-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_connect_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_connect_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27827-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>User-specific directories should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) userdir_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 A22  Rule ID: SV-33221r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 W20  Rule ID: SV-36614r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28120-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28038-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27670-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27999-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27715-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's scoreboard file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27606-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's scoreboard (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28102-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27572-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27853-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27982-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "ExecCGI" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28113-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28064-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28037-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27762-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28206-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27769-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "SymLinksIfOwnerMatch" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SymLinksIfOwnerMatch / -SymLinksIfOwnerMatch / +SymLinksIfOwnerMatch / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27748-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "TraceEnable" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) on / off / extended</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: TraceEnable directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 A22  Rule ID: SV-33227r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 W22  Rule ID: SV-33183r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28152-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's listening IP address should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IP-address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27419-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's listening port should be configured appropriately.</description>
      <parameters>
        <parameter>(1) port number</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28163-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ScriptAlias for the specified directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) url-path</parameter>
        <parameter>(2) TARGET: directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ScriptAlias directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 A22  Rule ID: SV-33229r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 W22  Rule ID: SV-33185r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28111-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Automatic directory indexing should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) autoindex_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 A22  Rule ID: SV-33219r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 W20  Rule ID: SV-36620r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28070-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 A22  Rule ID: SV-33232r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 W22  Rule ID: SV-33237r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28091-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 16. Limiting HTTP Request Methods p25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 A22  Rule ID: SV-33236r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 W22  Rule ID: SV-33238r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28033-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionShares </technical_mechanism>
        <technical_mechanism>(2) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 W22  Rule ID: SV-33109r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28007-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The maximum password age setting for Apache's service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The service account used to run the web service must have its password changed at least    annually.
STIG ID: WG060 W22  Rule ID: SV-36489r1_rule  Vuln ID: V-2235
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27628-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 W22  Rule ID: SV-33072r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27412-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28042-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27990-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's htpasswd.exe file(s) should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 W22  Rule ID: SV-36561r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28114-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27605-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27226-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27575-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28134-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27271-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /config directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28147-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28005-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28188-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28195-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The requried permssions for the file %SystemRoot%\System32\wscript.exe should be assigned.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\wscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28056-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The required permissions for the file %SystemRoot%\System32\cscript.exe should be assigned</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\cscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27816-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache web server be run with the appropriate privileges.</description>
      <parameters>
        <parameter>(1) Account type: ( privileged / non privileged )</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) My Computer / Manage / Configuration / Local Users and Groups / &lt;account name&gt;</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server, although started by superuser or privileged account, must run using a non-privileged account.
STIG ID: WG275 W22  Rule ID: SV-36607r1_rule  Vuln ID: V-13619
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27732-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 W22  Rule ID: SV-33177r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27466-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 W22  Rule ID: SV-33178r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28229-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 14. Authentication Mechanisms p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27438-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28235-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27975-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Server Administrator email address should be set correctly.</description>
      <parameters>
        <parameter>(1) email address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 'ServerAdmin' line in Apache configuration file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27783-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27765-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 21. Deny HTTP TRACE Requests with Mod_Rewrite p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28057-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27894-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27953-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27454-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27927-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27530-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28220-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 5. Lock Down the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28191-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28003-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28224-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28002-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28159-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28024-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28259-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27834-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28187-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28151-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27645-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28132-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28249-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27281-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27346-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27945-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28210-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28211-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28157-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28230-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28173-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28263-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28260-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27653-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28080-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28165-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28252-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24-25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28045-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27779-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionShares </technical_mechanism>
        <technical_mechanism>(2) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 W22  Rule ID: SV-33109r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27516-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 W22  Rule ID: SV-36644r1_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27868-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The maximum password age setting for Apache's service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The service account used to run the web service must have its password changed at least    annually.
STIG ID: WG060 W22  Rule ID: SV-36489r1_rule  Vuln ID: V-2235
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27830-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apachce "MaxKeepAliveRequests" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxKeepAliveRequests directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable) 
Add or modify the MaxKeepAliveRequests directive in the Apache configuration to have a value of 100 or more. p71</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 W22  Rule ID: SV-33105r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 A22  Rule ID: SV-33018r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27745-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All readable Apache web document directories should have their default webpage configured appropriately.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directories (from Apache configuration file: DocumentRoot directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 W22  Rule ID: SV-33107r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27780-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 W22  Rule ID: SV-33072r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27782-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's log_config_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) log_config_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.2 Enable the Log Config Module (Level 1, Scorable)
For dynamically loaded modules, add or modify the LoadModule directive so that it is present in the apache configuration as below and not commented out : LoadModule log_config_module modules/mod_log_config.so p12</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 W22  Rule ID: SV-33132r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 A22  Rule ID: SV-33025r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27839-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27750-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27599-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's htpasswd.exe file(s) should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 W22  Rule ID: SV-36561r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27799-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27705-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27840-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27771-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27843-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27240-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /config directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27829-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27306-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27813-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27773-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache site's robots.txt should be configured to disallow paths and files as appropriate.</description>
      <parameters>
        <parameter>(1) User-Agent</parameter>
        <parameter>(2) Disallowed path(s)|file(s)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) robots.txt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 W22  Rule ID: SV-28798r2_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 A22  Rule ID: SV-33028r1_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27872-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's ssl_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ssl_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.7.1 Install mod_ssl and/or mod_nss (Level 1, Scorable)
Ensure the mod_ssl and/or mod_nss is loaded in the Apache configuration: # httpd -M | egrep 'ssl_module|nss_module' p59</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27740-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache SSLProtocol directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SSLv2 / SSLv3 / TLSv1 / All</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLProtocol directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.7.4 Restrict weak SSL Protocols and Ciphers (Level 1, Scorable)
Add or modify the following line in the Apache server level configuration and every virtual host that is SSL enabled: SSLProtocol -ALL +SSLv3 +TLSv1 p65</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27576-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache SSLEngine directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27753-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The requried permssions for the file %SystemRoot%\System32\wscript.exe should be assigned.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\wscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27598-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The required permissions for the file %SystemRoot%\System32\cscript.exe should be assigned</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\cscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27380-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.8.1 Limit Information in the Server Token (Level 1, Scorable)
Add or modify the ServerTokens directive as shown below to have the value of Prod or ProductOnly: ServerTokens Prod page 68</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 W22  Rule ID: SV-33098r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 A22  Rule ID: SV-36672r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27686-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache web server be run with the appropriate privileges.</description>
      <parameters>
        <parameter>(1) Account type: ( privileged / non privileged )</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) My Computer / Manage / Configuration / Local Users and Groups / &lt;account name&gt;</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server, although started by superuser or privileged account, must run using a non-privileged account.
STIG ID: WG275 W22  Rule ID: SV-36607r1_rule  Vuln ID: V-13619
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27469-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All Apache's online manual should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) manual in the Server Root directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.4 Remove Default HTML Content (Level 1, Scorable)
Remove the Apache user manual content or comment out configurations referencing the manual # yum erase httpd-manual page 37</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27870-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.5 Remove Default CGI Content printenv (Level 1, Scorable)
Remove the printenv default CGI in cgi-bin directory if it is installed. # rm $APACHE_PREFIX/cgi-bin/printenv page 39</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27639-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.2 Configure the Access Log (Level 1, Scorable)
Add or modify the LogFormat directives in the Apache configuration to use the standard and recommended combined format show as shown below. LogFormat "%h %l %u %t \"%r\" %&gt;s %b \"%{Referer}i\" \"%{User-agent}i\"" combined</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p30</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 W22  Rule ID: SV-28654r2_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 A22  Rule ID: SV-36642r1_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27688-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the Timeout directive in the Apache configuration to have a value of 10 seconds or shorter. Timeout 10 page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 W22  Rule ID: SV-32980r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 A22  Rule ID: SV-32977r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27456-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the KeepAlive directive in the Apache configuration to have a value of On, so that Keepalive connections are enabled. KeepAlive On page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 W22  Rule ID: SV-32987r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 A22  Rule ID: SV-32844r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27330-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the KeepAliveTimeout directive in the Apache configuration to have a value of 15 or less. KeepAliveTimeout 15 page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 W22  Rule ID: SV-32880r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 A22  Rule ID: SV-32877r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27877-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
FollowSymLinks &amp; SymLinksIfOwnerMatch – The following of symbolic links is not recommended and should be disabled if possible. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 W22  Rule ID: SV-33001r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 A22  Rule ID: SV-40129r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27764-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories Includes &amp; IncludesNOEXEC – The IncludesNOEXEC option should only be needed when server side includes are required. The full Includes option should not be used as it also allows execution of arbitrary shell commands. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 W22  Rule ID: SV-33003r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27666-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories Includes &amp; IncludesNOEXEC – The IncludesNOEXEC option should only be needed when server side includes are required. The full Includes option should not be used as it also allows execution of arbitrary shell commands. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 W22  Rule ID: SV-33003r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27757-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
Multiviews – Is appropriate if content negotiation is required such as for multiple language are supported. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 W22  Rule ID: SV-33004r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 A22  Rule ID: SV-32754r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27657-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
Indexes – The Indexes option causes automatic generation of indexes, if the default index page is missing, and should be disabled unless required. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 W22  Rule ID: SV-33006r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 A22  Rule ID: SV-32755r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27618-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestBody directive in the Apache configuration to have a value of 102400 (100K) or less. Please read the Apache documentation so that it is understood that this directive will limit the size of file up-loads to the web server. LimitRequestBody 102400 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 W22  Rule ID: SV-33008r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 A22  Rule ID: SV-32756r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass+G66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27741-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestFields directive in the Apache configuration to have a value of 100 or less. If the directive is not present the default depends on a compile time configuration, but defaults to a value of 100. LimitRequestFields 100 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 W22  Rule ID: SV-33009r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 A22  Rule ID: SV-32757r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27554-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestFieldsize directive in the Apache configuration to have a value of 1024 or less. LimitRequestFieldsize 1024 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 W22  Rule ID: SV-33010r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 A22  Rule ID: SV-32766r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27426-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestline directive in the Apache configuration to have a value of 512 or shorter. LimitRequestline 512 page 72</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 W22  Rule ID: SV-33011r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 A22  Rule ID: SV-32768r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27822-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.1 Configure the Error Log (Level 1, Scorable)
Add an ErrorLog directive if not already configured. The file path may be relative or absolute, or the logs may be configured to be sent to a syslog server. ErrorLog "logs/error_log" Add a similar ErrorLog directive for each virtual host configured if the virtual host will have different people responsible for the web site. Each responsible individual or organization needs access to their own web logs, and needs the skills/training/tools for monitor the logs. page 50</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.5 Syslog Logging p44-45</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 W22  Rule ID: SV-33147r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 A22  Rule ID: SV-33192r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27794-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.2 Configure the Access Log (Level 1, Scorable)
Add or modify the CustomLog directives in the Apache configuration to use the combined format with an appropriate log file, syslog facility or piped logging utility. CustomLog log/access_log combined
Add a similar CustomLog directives for each virtual host configured if the virtual host will have different people responsible for the web site. Each responsible individual or organization needs access to their own web logs, and needs the skills/training/tools for monitor the logs. page 51</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 W22  Rule ID: SV-33151r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 A22  Rule ID: SV-33206r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27879-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.1 Configure the Error Log (Level 1, Scorable)
Add or modify the LogLevel in the apache configuration to have a value of notice or lower. Note that is it is compliant to have a value of info or debug if there is a need for a more verbose log and the storage and monitoring processes are capable of handling the extra load. The recommended value is notice. LogLevel notice page 50</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 W22  Rule ID: SV-33153r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 A22  Rule ID: SV-33207r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27132-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.3 Disable WebDAV modules (Level 1, Scorable)
For dynamically loaded modules comment out or remove the LoadModule directive for mod_dav, and mod_dav_fs modules the from the httpd.conf file. ##LoadModule dav_module modules/mod_dav.so ##LoadModule dav_fs_module modules/mod_dav_fs.so page 13</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27861-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_fs_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_fs_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.3 Disable WebDAV modules (Level 1, Scorable)
For dynamically loaded modules comment out or remove the LoadModule directive for mod_dav, and mod_dav_fs modules the from the httpd.conf file. ##LoadModule dav_module modules/mod_dav.so ##LoadModule dav_fs_module modules/mod_dav_fs.so page 13</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27583-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_lock_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_lock_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27852-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's info_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) info_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.8 Disable Info module (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_info in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for the mod_info module from the httpd.conf file. ##LoadModule info_module modules/mod_info.so Page 18</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W22  Rule ID: SV-33171r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27357-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's status_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) status_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.4 Disable Status module (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script with the --disable-status configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure --disable-status
b) For dynamically loaded modules comment out or remove the LoadModule directive for the mod_status module from the httpd.conf file. ##LoadModule status_module modules/mod_status.so page 14</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W22  Rule ID: SV-33171r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27825-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_module modules/mod_proxy.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27788-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_ftp_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_ftp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_ftp_module modules/mod_proxy_ftp.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27881-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_http_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_http_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_http_module modules/mod_proxy_http.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27579-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_connect_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_connect_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_connect_module modules/mod_proxy_connect.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27824-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_ajp_module should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>(1) proxy_ajp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_connect_module modules/mod_proxy_ajp.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27887-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_balancer_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_balancer_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_balancer_module modules/mod_proxy_balancer.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27682-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>User-specific directories should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) userdir_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.7 Disable User Directories Modules (Level 1, Scorable)
1. For source builds with static modules run the Apache ./configure script with the --disable-userdir configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure --disable-userdir
2. For dynamically loaded modules comment out or remove the LoadModule directive for mod_userdir module from the httpd.conf file. ##LoadModule userdir_module modules/mod_userdir.so Page 17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 W22  Rule ID: SV-33175r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 A22  Rule ID: SV-33221r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27845-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 W22  Rule ID: SV-33177r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27819-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 W22  Rule ID: SV-33178r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27510-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Ensure there is a single Order directive and set the value to deny, allow Page 27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27415-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Remove any Allow directives from the root &lt;Directory&gt; element. allow Page 27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27684-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Ensure there is a Deny directive, and set the value to from all. allow Page 27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27067-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "ExecCGI" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27134-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27679-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27506-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27545-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27692-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27806-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "SymLinksIfOwnerMatch" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SymLinksIfOwnerMatch / -SymLinksIfOwnerMatch / +SymLinksIfOwnerMatch / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27531-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "TraceEnable" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) on / off / extended</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: TraceEnable directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.8 Disable HTTP TRACE Method (Level 1, Scorable)
Add a TraceEnable directive to the server level configuration with a value of off. Server level configuration is the top level configuration, not nested within any other directives like &lt;Directory&gt; or &lt;Location&gt;. TraceEnable off Page 42-43</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 W22  Rule ID: SV-33183r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 A22  Rule ID: SV-33227r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27862-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's listening IP address should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IP-address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.3 Restrict Listen Directive (Level 2, Scorable)
The Apache Listen directive specifies the IP addresses and port numbers the Apache web server will listen for requests. Rather than be unrestricted to listen on all IP addresses available to the system, the specific IP address or addresses intended should be explicitly specified. Specifically a Listen directive with no IP address specified, or with an IP address of zeros should not be used.  Page 74</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27246-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's listening port should be configured appropriately.</description>
      <parameters>
        <parameter>(1) port number</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.3 Restrict Listen Directive (Level 2, Scorable)
The Apache Listen directive specifies the IP addresses and port numbers the Apache web server will listen for requests. Rather than be unrestricted to listen on all IP addresses available to the system, the specific IP address or addresses intended should be explicitly specified. Specifically a Listen directive with no IP address specified, or with an IP address of zeros should not be used.  Page 74</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27733-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ScriptAlias for the specified directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) url-path</parameter>
        <parameter>(2) TARGET: directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ScriptAlias directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 W22  Rule ID: SV-33185r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 A22  Rule ID: SV-33229r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27759-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Automatic directory indexing should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) autoindex_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.5 Disable Autoindex module (Level 1, Scorable)
For source builds with static modules run the Apache ./configure script with the --disable-autoindex configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure –disable-autoindex
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_autoindex module the from the httpd.conf file. ## LoadModule autoindex_module modules/mod_autoindex.so Page 14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 W22  Rule ID: SV-33225r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 A22  Rule ID: SV-33219r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27536-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.3 Restrict OverRide for the OS Root Directory (Level 1, Scorable)
Set the value for AllowOverride to None. Page 30-31</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 W22  Rule ID: SV-33237r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 A22  Rule ID: SV-33232r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27776-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.7 Limit HTTP Request Methods (Level 1, Scorable)
For normal web server operation, you will typically need to allow only the GET, HEAD and POST request methods. Page 40-41</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 W22  Rule ID: SV-33238r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 A22  Rule ID: SV-33236r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27677-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with nfs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>AC-3(4).1
CM-6.1 (ii)
CM-7.1 (ii)</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>CCI-001362
CCI-001588
CCI-000381</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27612-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with smb should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/samba/smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27000-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27890-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27648-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27400-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The file permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27304-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27876-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27864-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27724-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27494-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27481-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27332-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27873-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27292-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27282-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27777-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27619-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27884-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27384-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27772-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27492-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27664-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27627-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27672-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27460-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27787-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27548-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27826-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26950-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27833-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27800-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27911-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
Perform the following to set the permissions on the $APACHE_PREFIX directories, and then remove other read permissions on the bin directory and its contents:
23 | P a g e
# chmod –R u=rwX,g=rX,o=rX $APACHE_PREFIX # chmod –R u=rwX,g=rX,o=X $APACHE_PREFIX/bin  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27709-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27685-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27540-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27818-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27602-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27041-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate. … exception in some cases may have a designated group with write access for the Apache web document root ($APACHE_PREFIX/htdocs) are likely to need a designated group to allow web content to be updated.</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27699-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27866-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
the Apache web document root ($APACHE_PREFIX/htdocs) are likely to need a designated group to allow web content to be updated (such as webupdate) through a change management process. Page 21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27793-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /cgi-bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27919-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27820-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27435-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf StartServers directive must be set properly.
STIG ID: WA000-WWA026 A22  Rule ID: SV-36645r1_rule  Vuln ID: V-13727
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27449-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MinSpareServers directive must be set properly. 
STIG ID: WA000-WWA028 A22  Rule ID: SV-36646r1_rule  Vuln ID: V-13728
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27810-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxSpareServers directive must be set properly. 
STIG ID: WA000-WWA030 A22  Rule ID: SV-36648r1_rule  Vuln ID: V-13729
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27848-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxClients directive must be set properly. 
STIG ID: WA000-WWA032 A22  Rule ID: SV-36649r1_rule  Vuln ID: V-13730
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27696-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the permissions so that the directory is only writable by root, or the user under which apache initially starts up (default is root), Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27851-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27930-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27126-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the permissions so that the directory is only writable by root, or the user under which apache initially starts up (default is root), Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27815-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's scoreboard file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27859-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's scoreboard (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27667-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.10 Restrict Access to .ht* files (Level 1, Scorable)
Also a common name for web password and group files is .htpasswd and .htgroup. Neither of these files should be placed in the document root Page 45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27756-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Configure the Apache user and group in the Apache configuration file httpd.conf: User apache Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27566-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Configure the Apache user and group in the Apache configuration file httpd.conf: Group apache Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27883-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.8.2 Limit Information in the Server Signature (Level 1, Scorable)
Add or modify the ServerSignature directive as shown below to have the value of Off: ServerSignature Off Page 68-69</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27903-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.9 Restrict HTTP Protocol Versions (Level 1, Scorable)
Add the RewriteEngine directive to the configuration within the global server context with the value of on so that the rewrite engine is enabled. RewriteEngine On Page 43-44</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.11 Restrict HTTP Protocol Version p19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27791-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27910-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27680-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27390-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27860-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27817-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27781-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.3 Lock the Apache User Account (Level 1, Scorable)
Use the passwd command to lock the apache account: # passwd -l apache Page 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27878-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Although Apache typically is started with root privileges in order to listen on port 80 and 443, it can and should run as another non-root user in order to perform the web services. Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27722-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Although Apache typically is started with root privileges in order to listen on port 80 and 443, it can and should run as another non-root user in order to perform the web services. Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27302-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27700-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27837-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27856-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27841-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27854-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27714-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must be owned by root and have a group ownership of the Apache group (as defined via the Group directive)
# chown root:apache /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27422-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must be owned by root and have a group ownership of the Apache group (as defined via the Group directive)
# chown root:apache /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27943-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must have no read-write-search access permission for other users.
# chmod o-rwx /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27497-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27601-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27462-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27217-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27273-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27915-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27935-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26955-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27901-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27519-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27892-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27509-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27382-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27944-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27897-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "ExecCGI" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27882-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for all DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Order directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.7 Limit HTTP Request Methods (Level 1, Scorable)
Search for the &lt;Directory&gt; directive on the document root directory … Ensure that the access control order within the &lt;Directory&gt; directive is allow, deny. Order allow,deny Page 41</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27313-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) TARGET: Directory directive</technical_mechanism>
        <technical_mechanism>(2) Apache configuration file: Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Add a single Order directive and set the value to deny, allow. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26965-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Include the appropriate Allow and Deny directives, with values that are appropriate for the purposes of the directory. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27023-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Include the appropriate Allow and Deny directives, with values that are appropriate for the purposes of the directory. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27913-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.6 Remove Default CGI Content test-cgi (Level 1, Scorable)
Remove the test-cgi default CGI in cgi-bin directory if it is installed. # rm $APACHE_PREFIX/cgi-bin/test-cgi Page 39-40</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19088-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow basic authentication" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowBasicAuthentication |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19184-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow simple passwords" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowSimplePasswords |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19107-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow unmanaged devices" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowUnmanagedDevices |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19178-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure dial plan security" setting should be configured correctly.</description>
      <parameters>
        <parameter>Unsecured, SIPSecured, Secured</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DialPlanSecure |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19098-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure login authentication for IMAP4" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType IMAP4LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18657-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure login authentication for POP3" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType POP3LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19200-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure Protocol logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>Verbose, None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProtocolLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18409-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure Sender Filtering" setting should be configured correctly.</description>
      <parameters>
        <parameter>StampStatus, Reject</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderFiltering |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19203-9' platform='exchange2007' modified='2012-02-24'>
      <description>The "Do not permamently delete items until the database has been backed up" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RetainDeletedItemsUntilBackup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19015-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable automatic forwards to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticForwardsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19198-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable automatic replies to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticRepliesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19207-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable non-delivery reports to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NonDeliveryReportsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19191-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable OOF messages to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>External, ExternalLegacy, None, and InternalLegacy</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType OofMessagesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18405-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable S/MIME for OWA 2007" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SMimeEnabled2007 |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19150-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable Sender ID agent" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderID |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19035-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable Sender Reputation" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderReputation |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19205-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enforce Password History" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 50 passwords</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType EnforcePasswordHistory |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19116-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: DNS Routing" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDNSRoutingEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19112-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: Domain Security" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDomainSecureEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18256-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: Ignore Start TLS" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthIgnoreSTARTTLS |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19188-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Keep deleted mailboxes for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 24855 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType KeepDeletedMailboxes |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19239-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Issue warning at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MailboxApproachingStorageLimitWarning |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19195-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Prohibit send and receive at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendReceiveQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18295-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Prohibit send at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18314-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum number of recipients - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 recipients</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumNumberRecipients |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18897-9' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum receive size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19036-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum receive size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18354-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum send size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19165-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum send size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18561-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Message tracking logging - Mailbox" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingMailbox |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19093-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Message tracking logging - Transport" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingTransport |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19329-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Active Directory Topology" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Active Directory Topology </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeADTopology\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19214-6' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange ADAM" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange ADAM </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADAM_MSExchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19294-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Anti-spam Update" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Anti-spam Update</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAntispamUpdate\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19174-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Credential Service (Exchange 2007)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Credential Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EdgeCredentialSvc\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19234-4' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange EdgeSync Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange EdgeSync Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeSync\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19213-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange File Distribution" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange File Distribution </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFDS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19155-1' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange IMAP4" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange IMAP4 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIMAP4\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19120-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Information Store" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Information Store </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19268-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mail Submission Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mail Submission Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailSubmission\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19193-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Assistants" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Assistants </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxAssistants\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19171-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Monitoring" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Monitoring </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMonitoring\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19108-0' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange POP3" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange POP3 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangePOP3\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19334-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Replication Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Replication Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRepl\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19243-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Search Indexer" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Search Indexer </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19139-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Server Extension for Windows Server Backup" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Server Extension for Windows Server Backup </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wsbexchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19144-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19134-6' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Speech Engine Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Speech Engine Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSSpeechService\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18914-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange System Attendant" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange System Attendant </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19020-7' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransport\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19303-7' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport Log Search" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport Log Search </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransportLogSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19008-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Unified Messaging" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Unified Messaging </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeUM\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19055-3' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Search (Exchange)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Search (Exchange) </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msftesql-Exchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19185-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "Minimum password length" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 16</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MinimumPasswordLength |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19054-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mount database at startup" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MountDatabaseAtStartup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19310-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Number of attempts allowed" setting should be configured correctly.</description>
      <parameters>
        <parameter>4 - 16 Attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NumberAttemptsAllowed |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19349-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Password Expiration" setting should be configured correctly.</description>
      <parameters>
        <parameter>1:00:00:00 - 730:00:00:00 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PasswordExpiration |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19264-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Refresh interval" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 596523 Hours</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RefreshInterval |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19149-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require alphanumeric password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireAlphanumericPassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19251-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require Client Certificates" setting should be configured correctly.</description>
      <parameters>
        <parameter>Ignore, Accepted, or Required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientCertificates |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19351-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require encryption on device" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireEncryptionOnDevice |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19194-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequirePassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19285-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Retain deleted items for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 30 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DeletedItemRetention |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19280-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Time without user input before password must be re-entered" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 60 Minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaxInactivityTimeDeviceLock |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19339-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Turn on Connectivity logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ConnectivityLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19327-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Turn on script execution" setting should be configured correctly.</description>
      <parameters>
        <parameter>Restricted/ AllSigned/ RemoteSigned/ Unrestricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExecutionPolicy |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19141-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow access to voicemail without requiring a PIN" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PinlessAccessToVoicemail |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19132-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow basic authentication" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowBasicAuthentication |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18357-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow simple passwords" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowSimplePasswords |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18866-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow unmanaged devices" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowUnmanagedDevices |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19115-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure dial plan security" setting should be configured correctly.</description>
      <parameters>
        <parameter>Unsecured, SIPSecured, Secured</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DialPlanSecure |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18176-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure login authentication for IMAP4" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType IMAP4LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19077-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure login authentication for POP3" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType POP3LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18924-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure Protocol logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>Verbose, None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProtocolLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18693-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure Sender Filtering" setting should be configured correctly.</description>
      <parameters>
        <parameter>StampStatus, Reject</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderFiltering |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18710-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure startup mode" setting should be configured correctly.</description>
      <parameters>
        <parameter>TCP, Dual, TLS</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType UMStartupMode |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18273-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Do not permamently delete items until the database has been backed up" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RetainDeletedItemsUntilBackup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18842-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable automatic forwards to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticForwardsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19131-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable automatic replies to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticRepliesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19057-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable non-delivery reports to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NonDeliveryReportsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19022-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable OOF messages to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>External, ExternalLegacy, None, and InternalLegacy</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType OofMessagesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19096-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable S/MIME for OWA 2010" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SMimeEnabled2010 |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18208-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable Sender ID agent" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderID |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18326-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable Sender Reputation" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderReputation |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19013-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enforce Password History" setting should be configured correctly.</description>
      <parameters>
        <parameter>0-50 passwords</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType EnforcePasswordHistory |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19081-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: DNS Routing" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDNSRoutingEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18182-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: Domain Security" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDomainSecureEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18214-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: Ignore Start TLS" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthIgnoreSTARTTLS |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19076-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Keep deleted mailboxes for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 24855 days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType KeepDeletedMailboxes |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18662-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Issue warning at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MailboxApproachingStorageLimitWarning |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18281-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Prohibit send and receive at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendReceiveQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18515-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Prohibit send at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18506-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum number of recipients - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 recipients</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumNumberRecipients |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19113-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum receive size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19010-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum receive size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18590-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum send size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19156-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum send size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18647-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Message tracking logging - Mailbox" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingMailbox |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19094-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Message tracking logging - Transport" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingTransport |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18530-6' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Active Directory Topology" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Active Directory Topology </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeADTopology\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19176-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange ADAM" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange ADAM </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADAM_MSExchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18189-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Address Book" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Address Book</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAB\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19179-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Anti-spam Update" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Anti-spam Update</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAntispamUpdate\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19126-2' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Credential Service (Exchange 2010)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Credential Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeCredential\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19164-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange EdgeSync Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange EdgeSync Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeSync\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18421-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange File Distribution" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange File Distribution </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFDS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19181-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Forms-Based Authentication service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Forms-Based Authentication service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFBA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18945-6' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange IMAP4" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange IMAP4 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIMAP4\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18199-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Information Store" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Information Store </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18635-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mail Submission Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mail Submission Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailSubmission\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19083-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Assistants" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Assistants </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxAssistants\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19066-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Replication" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Replication </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxReplication\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19100-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Monitoring" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Monitoring </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMonitoring\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18778-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange POP3" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange POP3 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangePOP3\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18352-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Protected Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Protected Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeProtectedServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18595-9' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Replication Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Replication Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRepl\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19101-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange RPC Client Access" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange RPC Client Access </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRPC\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19031-4' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Search Indexer" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Search Indexer </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18203-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Server Extension for Windows Server Backup" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Server Extension for Windows Server Backup </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wsbexchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19109-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19136-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Speech Engine Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Speech Engine Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSSpeechService\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18212-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange System Attendant" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange System Attendant </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19201-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Throttling" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Throttling </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeThrottling\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18234-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransport\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19208-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport Log Search" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport Log Search </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransportLogSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19121-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Unified Messaging" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Unified Messaging </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeUM\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18373-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Search (Exchange)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Search (Exchange) </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msftesql-Exchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18241-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Minimum password length" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 to 16 characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MinimumPasswordLength |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19042-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mount database at startup" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MountDatabaseAtStartup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19190-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Number of attempts allowed" setting should be configured correctly.</description>
      <parameters>
        <parameter>4 - 16 Attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NumberAttemptsAllowed |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19215-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Password Expiration" setting should be configured correctly.</description>
      <parameters>
        <parameter>1:00:00:00 - 730:00:00:00 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PasswordExpiration |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19091-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Refresh interval" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 596523 Hours</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RefreshInterval |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19177-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require alphanumeric password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireAlphanumericPassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19221-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require Client Certificates" setting should be configured correctly.</description>
      <parameters>
        <parameter>Ignore, Accepted, or Required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientCertificates |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18242-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require client MAPI encryption" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientMAPIEncryption |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19202-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require encryption on device" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireEncryptionOnDevice |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19162-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequirePassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19241-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Retain deleted items for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 30 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DeletedItemRetention |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18432-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Time without user input before password must be re-entered" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 60 Minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaxInactivityTimeDeviceLock |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19153-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on Administrator Audit Logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AdministratorAuditLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19219-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on Connectivity logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ConnectivityLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19240-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on script execution" setting should be configured correctly.</description>
      <parameters>
        <parameter>Restricted/ AllSigned/ RemoteSigned/ Unrestricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExecutionPolicy |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5435-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/export/home should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6030-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/var should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5936-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/opt should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6122-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The shell for the root account should be located on the appropriate filesystem</description>
      <parameters>
        <parameter>filesystem</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6091-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6249-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The read-only SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6095-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The read/write SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6108-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should ban or allow usernames or UIDs in passwords as appropriate</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5812-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should ban or allow words found in a dictionary as appropriate.</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6161-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should enforce the correct amount of special characters</description>
      <parameters>
        <parameter>number of special characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6172-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should enforce or not enforce the requirement to have mixed case passwords as appropriate.</description>
      <parameters>
        <parameter>enforce/not enforce</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5639-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The minimum password age should be set as appropriate</description>
      <parameters>
        <parameter>number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6163-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The minimum required password length should be set as appropriate</description>
      <parameters>
        <parameter>number of characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5982-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Password history should be saved for an appropriate number of password changes</description>
      <parameters>
        <parameter>number of password changes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5956-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The number of consecutive failed login attempts required to trigger a lockout should be set as appropriate</description>
      <parameters>
        <parameter>number of consecutive failed login attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6219-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Login access to accounts without passwords should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/shadow</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5925-3' platform='hpux11.23' modified='2009-04-30'>
      <description>New users should be required or not required to change their password on first login as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6140-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Access to single-user mode (maintainence mode) should require the root password or not as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6180-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The delay between failed logins should be set as appropriate</description>
      <parameters>
        <parameter>number of seconds</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6114-3' platform='hpux11.23' modified='2009-04-30'>
      <description>All files should be owned by an existing account or not as appropriate.</description>
      <parameters>
        <parameter>existing account required / existing account not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6120-0' platform='hpux11.23' modified='2009-04-30'>
      <description>All files should be owned by an existing group or not as appropriate.</description>
      <parameters>
        <parameter>existing group required / existing group not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6094-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The console login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/login.cfg</technical_mechanism>
        <technical_mechanism>via /etc/motd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5561-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The SSH login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5583-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The telnet login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via telnetd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5552-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The ftp login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5255-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The graphical login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6043-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Accounts other than root should be allowed to have the UID 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6117-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Accounts other than root and locked system accounts should be allowed to have a GID of 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5883-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Each account should be assigned a unique UID or not as appropriate</description>
      <parameters>
        <parameter>unique/not unique</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5261-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The ftp account should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5495-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Login accounts should include an appropriate GECOS identifier or no GECOS identifier</description>
      <parameters>
        <parameter>GECOS value, null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4.1 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5949-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The screen lock should activate after an appropriate period of inactivity</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xscreensaver</technical_mechanism>
        <technical_mechanism>via dtsession</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6147-3' platform='hpux11.23' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all shell executables.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6182-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Remote (serial) consoles should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inittab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5764-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Root logins should be restricted to the console or not as appropriate.</description>
      <parameters>
        <parameter>restricted/not restricted</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6151-5' platform='hpux11.23' modified='2009-04-30'>
      <description>.netrc files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5516-0' platform='hpux11.23' modified='2009-04-30'>
      <description>.rhosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6089-7' platform='hpux11.23' modified='2009-04-30'>
      <description>.shosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5873-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/hosts.equiv file should exist or not as appropriate.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6186-1' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/shells file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (11)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6191-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Shells referenced in /etc/passwd should be included in /etc/shells or not as appropriate</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8640-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/passwd file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8240-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/shadow file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8631-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/group file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6208-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Groups referenced in /etc/passwd should be included in /etc/group or not as appropriate.</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (15)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5265-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The home directory for the root account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (16)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6133-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The home directory for each user account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
        <technical_mechanism>via /usr/sbin/useradd</technical_mechanism>
        <technical_mechanism>via /etc/default/useradd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (17)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5797-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories referenced in /etc/passwd should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (18)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5886-7' platform='hpux11.23' modified='2009-04-30'>
      <description>All device files should be located inside an appropriate path</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (24)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5762-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The ntpd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5987-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The Network Time Protocol (ntp) synchronization server should be set appropriately.</description>
      <parameters>
        <parameter>timeserver</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via ntpd.conf</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5828-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The default gateway should be set appropriately.</description>
      <parameters>
        <parameter>IP address/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/default/route.conf</technical_mechanism>
        <technical_mechanism>via /etc/gated.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5927-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The inetd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6143-2' platform='hpux11.23' modified='2009-04-30'>
      <description>echo service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6054-1' platform='hpux11.23' modified='2009-04-30'>
      <description>netstat service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6010-3' platform='hpux11.23' modified='2009-04-30'>
      <description>rcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5460-1' platform='hpux11.23' modified='2009-04-30'>
      <description>chargen service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5618-4' platform='hpux11.23' modified='2009-04-30'>
      <description>finger service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5838-8' platform='hpux11.23' modified='2009-04-30'>
      <description>tftpd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5878-4' platform='hpux11.23' modified='2009-04-30'>
      <description>walld service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5266-2' platform='hpux11.23' modified='2009-04-30'>
      <description>rstatd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6138-2' platform='hpux11.23' modified='2009-04-30'>
      <description>sprayd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6057-4' platform='hpux11.23' modified='2009-04-30'>
      <description>rusersd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5885-9' platform='hpux11.23' modified='2009-04-30'>
      <description>rlogin service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5978-2' platform='hpux11.23' modified='2009-04-30'>
      <description>rsh service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5607-7' platform='hpux11.23' modified='2009-04-30'>
      <description>ftp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6075-6' platform='hpux11.23' modified='2009-04-30'>
      <description>telnet service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6232-3' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6171-3' platform='hpux11.23' modified='2009-04-30'>
      <description>inn service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5638-2' platform='hpux11.23' modified='2009-04-30'>
      <description>uucp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6175-4' platform='hpux11.23' modified='2009-04-30'>
      <description>rexec service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6144-0' platform='hpux11.23' modified='2009-04-30'>
      <description>font-service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #20</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5763-8' platform='hpux11.23' modified='2009-04-30'>
      <description>imap2 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5856-0' platform='hpux11.23' modified='2009-04-30'>
      <description>pop3 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6081-4' platform='hpux11.23' modified='2009-04-30'>
      <description>ident service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6093-9' platform='hpux11.23' modified='2009-04-30'>
      <description>rexd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6173-9' platform='hpux11.23' modified='2009-04-30'>
      <description>daytime service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5287-8' platform='hpux11.23' modified='2009-04-30'>
      <description>dtspc (cde-spc) service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6070-7' platform='hpux11.23' modified='2009-04-30'>
      <description>rquotad service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #28</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6026-9' platform='hpux11.23' modified='2009-04-30'>
      <description>cmsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6166-3' platform='hpux11.23' modified='2009-04-30'>
      <description>tooltalk service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5867-7' platform='hpux11.23' modified='2009-04-30'>
      <description>xdmcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5810-7' platform='hpux11.23' modified='2009-04-30'>
      <description>discard service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5898-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5713-3' platform='hpux11.23' modified='2009-04-30'>
      <description>vino-server service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5994-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The bind service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6215-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The version string reported by the bind service should be configured appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/named.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5937-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The nfsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5303-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The mountd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6223-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The statd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6069-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The lockd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5320-7' platform='hpux11.23' modified='2009-04-30'>
      <description>NFS should be configured with appropriate authentication methods</description>
      <parameters>
        <parameter>list of auth methods</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NFSvia</technical_mechanism>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5593-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The read-only (ro) option should be enabled or disabled as appropriate for all NFS exports.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6256-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The nosuid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5596-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The nosgid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6234-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6185-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The sendmail banner should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6000-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The decode sendmail alias should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/aliases</technical_mechanism>
        <technical_mechanism>via /usr/lib/aliases</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5551-7' platform='hpux11.23' modified='2009-04-30'>
      <description>.forward files should be allowed or disallowed as appropriate for all users</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via rm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6018-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Programs executed through the aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6141-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Programs executed through the aliases file should reside a directory with an appropriate user owner</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6233-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail vrfy command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5288-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail expn command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) h)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6113-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail should be configured with an appropriate logging level</description>
      <parameters>
        <parameter>logging level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6047-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail help command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sendmail</technical_mechanism>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) k)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6214-1' platform='hpux11.23' modified='2009-04-30'>
      <description>NIS+ server should operate at an appropriate security level</description>
      <parameters>
        <parameter>security level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NIS+</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6051-7' platform='hpux11.23' modified='2009-04-30'>
      <description>X-Windows should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5756-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Authorized X-clients should be listed or not in the X*.hosts file as appropriate</description>
      <parameters>
        <parameter>listed/not listed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/X*.hosts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5769-5' platform='hpux11.23' modified='2009-04-30'>
      <description>X-Windows should write .Xauthority files to users' home directories or not as appropriate</description>
      <parameters>
        <parameter>write/not write</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via xdm</technical_mechanism>
        <technical_mechanism>via gdm</technical_mechanism>
        <technical_mechanism>via kdm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5976-6' platform='hpux11.23' modified='2009-04-30'>
      <description>X11 forwarding via SSH should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5438-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6227-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'hosts allow' option should be configured with an appropriate set of networks</description>
      <parameters>
        <parameter>list of networks</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5290-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'security option' option should be set as appropriate</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6192-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'encrypt' passwords option should be set as appropriate</description>
      <parameters>
        <parameter>yes/no</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6165-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'smb passwd file' option should be set to an appropriate password file or no password file</description>
      <parameters>
        <parameter>file/nothing</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6262-0' platform='hpux11.23' modified='2009-04-30'>
      <description>IPv6 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via ifconfig</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6134-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/kmem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5315-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/mem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5912-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/null file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6128-3' platform='hpux11.23' modified='2009-04-30'>
      <description>resolv.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5322-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/named.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6231-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/at file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6082-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/rdist file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6121-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/sbin/sync file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5452-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Superuser account home directories' permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6280-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5332-2' platform='hpux11.23' modified='2009-04-30'>
      <description>smbpassword executable permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5782-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5861-0' platform='hpux11.23' modified='2009-04-30'>
      <description>File permissions should be set as appropriate for the log file configured to capture critical sendmail messages.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6248-9' platform='hpux11.23' modified='2009-04-30'>
      <description>All files executed through /etc/aliases file entries should have file permissions set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5592-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5336-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #38</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6205-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6298-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #40</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6331-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #41</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6300-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5938-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6027-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #44</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5864-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5757-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The /sbin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #46</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6207-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #47</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5973-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #48</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5341-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #49</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6291-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6306-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #51</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5358-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The /usr/bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #52</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6310-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #53</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5904-8' platform='hpux11.23' modified='2009-04-30'>
      <description>snmpd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #56</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6217-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #57</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5494-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #58</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6221-6' platform='hpux11.23' modified='2009-04-30'>
      <description>.Xauthority file permissions should be set appropriately for all users.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #60</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6314-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #61</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6327-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/cron.d/at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #62</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6032-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/cron.d/cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #63</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5915-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #64</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5990-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/default/* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #65</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6320-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/default/login file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6236-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/ftpusers file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #69</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5950-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/host.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5362-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hostname* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #71</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6068-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6271-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/inetd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #73</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6301-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/issue file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #75</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6275-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6319-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #77</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5649-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/mail/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5870-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/motd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #79</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6274-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/netconfig file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #80</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5372-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #81</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5439-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/pam.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #82</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5601-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #83</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6302-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #84</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5570-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/security file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #85</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6020-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #86</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5760-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #87</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5899-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #88</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6225-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/syslog.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #89</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6242-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6083-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/fstab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #91</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5683-8' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5933-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/loginlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #93</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6149-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/messages file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #94</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6039-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/sulog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #95</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5655-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/utmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #96</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5854-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/wtmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #97</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6349-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/authlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #98</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6067-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/syslog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #99</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5388-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5691-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #101</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5502-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/pt_chmod file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #103</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5682-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/embedded_us file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #104</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6259-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/sendmail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #105</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6210-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/kerberos/bin/rsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #107</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5871-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/spool/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5840-4' platform='hpux11.23' modified='2009-04-30'>
      <description>smbpassword file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #109</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6353-7' platform='hpux11.23' modified='2009-04-30'>
      <description>System files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5393-4' platform='hpux11.23' modified='2009-04-30'>
      <description>System files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5399-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Default/skeleton dot files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6179-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Default/skeleton dot files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6272-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5403-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5746-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5465-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5729-9' platform='hpux11.23' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5433-8' platform='hpux11.23' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5879-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5447-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6046-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5473-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5404-9' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6254-7' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5425-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6372-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6283-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6001-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5451-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should or should not contain world-writable files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
        <technical_mechanism>via profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5467-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should not contain the current directory as the first or last entry</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6455-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The current directory should or should not be added to the environmental variable PATH by global initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5486-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The current directory should or should not be added to the environmental variable PATH by local initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6337-0' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6289-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The system umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6451-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The user umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6042-6' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5556-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5887-5' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5962-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6365-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6211-7' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5491-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6313-1' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6159-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6065-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6251-3' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6290-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6360-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED in favor of CCE-8638-9, CCE-8647-0, and CCE-8187-7.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-8638-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.master file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8647-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.misc file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8187-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.net file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5504-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5517-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6076-4' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6292-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled for user accounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /tcb/files/auth/*</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6203-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled at boot time as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5794-3' platform='hpux11.23' modified='2009-04-30'>
      <description>System logons should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6168-9' platform='hpux11.23' modified='2009-04-30'>
      <description>System logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6014-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Password changes should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5983-2' platform='hpux11.23' modified='2009-04-30'>
      <description>su usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5859-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Creation/modification of superuser groups should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6326-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Clearing of the audit log file should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5894-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Startup/shutdown of audit functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6110-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Use of identification/authorization mechanisms should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6423-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Remote access from outside the corporate network should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6454-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Change of permissions/privileges should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6282-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should allow or deny write access to the terminal as appropriate</description>
      <parameters>
        <parameter>allow/deny</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.4 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6317-2' platform='hpux11.23' modified='2009-04-30'>
      <description>PRI audit file should be specified appropriately</description>
      <parameters>
        <parameter>file and path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5660-6' platform='hpux11.23' modified='2009-04-30'>
      <description>SEC audit file should be specified appropriately</description>
      <parameters>
        <parameter>file and path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6348-7' platform='hpux11.23' modified='2009-04-30'>
      <description>FileSpaceSwitch should be set to an appropriate value</description>
      <parameters>
        <parameter>percentage of free space</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5774-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Wakeup switchpoint frequency should be set to an appropriate time interval</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5731-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Warning messages switchpoint distance should be set to an appropriate value</description>
      <parameters>
        <parameter>switchpoint distance integer</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6444-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Hard core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5940-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Root logins should be allowed or not as appropriate from SSH consoles</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4017-0' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Use Only Machine Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Use_HKLM_only </technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-5</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1277, oval:org.mitre.oval:def:2050</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UseOnlyMachineSettings-LocalComputer, UseOnlyMachineSettings-LocalComputer-Disabled</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>use_only_machine_settings_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1277</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3924-8' platform='ie7' modified='2012-02-17'>
      <description>Internet Explorer Processes (Restrict ActiveX Install)</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved) </technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict ActiveX Install</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-119</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:658</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-RestrictActiveXInstall-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_RestrictActiveXInstall_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:658</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3929-7' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Do Not Allow Users to Add/Delete Sites" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_Zones_Map_Edit</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_zones_map_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-146</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1400</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersAddDeleteSites-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersAddDeleteSites_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1400</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3576-6' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoUpdateCheck</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-212</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1357</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisablePeriodicCheckForIESoftwareUpdates-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisablePeriodicCheckForIESoftwareUpdates_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1357</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4043-6' platform='ie7' modified='2012-02-17'>
      <description>Internet Explorer Processes (Zone Elevation Protection)</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved)</technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Protection From Zone Elevation</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved)</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-347</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:620</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ProtectionFromZoneElevation_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:620</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4047-7' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Consistent MIME Handling)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe</technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet E</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Binary Behavior Security Restriction</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved)</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-382</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:884</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-ConsistentMimeHandling-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ConsistentMimeHandling_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:884</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3941-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Software to Run or Install Even if the Signature is Invalid" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-449</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:680, oval:org.mitre.oval:def:1392</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowSoftwareRunInstallSignatureInvalid-LocalComputer, AllowSoftwareToRununOrInstallEvenIfSignatureInvalid-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowSoftwareRunInstallSignatureInvalid_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:680</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3338-1' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (MK Protocol)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/MK Protocol Security Restriction</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-591</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:617</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-MKProtocolSecurityRestriction-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_MKProtocolSecurityRestriction_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:617</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4118-6' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Software Update Shell Notifications on Program Launch" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoMSAppLogo5ChannelNotify</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-622</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1188</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableSoftwareUpdateShellNotifications-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableSoftwareUpdateShellNotifications_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1188</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4122-8' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Restrict File Download)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-668</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:320</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-RestrictFileDownload-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_RestrictFileDownload_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:320</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3518-8' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Automatic Install of Internet Explorer Components" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoJITSetup</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoJITSetup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-684</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1198</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAutomaticInstallOfIEComponents-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableAutomaticInstallOfIEComponents_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1198</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3201-1' platform='ie7' modified='2012-02-17'>
      <description>The "Make Proxy Settings Per-Machine (Rather Then Per-User)" setting should be configured correctly.</description>
      <parameters>
        <parameter>number of proxy settings</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser</technical_mechanism>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-693</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1181</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>MakeProxySettingsPerMachine-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>MakeProxySettingsPerMachine_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1181</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3744-0' platform='ie7' modified='2012-02-17'>
      <description>The "Do Not Allow Users to enable or Disable Add-Ons" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExtensionManagement</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-708</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1380, oval:org.mitre.oval:def:1358, oval:org.mitre.oval:def:1694</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersEnableDisableAddOns-LocalComputer, DoNotAllowUsersEnableDisableAddOns-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersEnableDisableAddOns_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1694</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3894-3' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off Crash Detection" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection</technical_mechanism>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-753</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:487</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffCrashDetection-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffCrashDetection_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:487</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4162-4' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Scripted Window Security Restrictions)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Scripted Window Security Restrictions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-827</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:465</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-ScriptedWindowSecurityRestrictions-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:465</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3933-9' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Do Not Allow Users to Change Policies" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-833</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1404</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersChangePolicies-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersChangePolicies_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1404</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4149-1' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (MIME Sniffing)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Mime Sniffing Safety Feature</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-985</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:317</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-MimeSniffingSafetyFeature-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_MimeSniffingSafetyFeature_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:317</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4026-1' platform='ie7' modified='2012-02-17'>
      <description>The "Check for Signature on Downloaded Programs" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\CheckExeSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1025</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:395</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>CheckSignatureDownloadedPrograms-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>CheckSignatureDownloadedPrograms_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:395</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4171-5' platform='ie7' modified='2012-02-17'>
      <description>The "Do Not Allow Resetting Internet Explorer Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableRIED</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-42</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:583</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowResettingIESettings-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowResettingIESettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:583</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4109-5' platform='ie7' modified='2012-02-17'>
      <description>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-49</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:506, oval:org.mitre.oval:def:533</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:506</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3378-7' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-863</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1119</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffFirst-RunOpt-In-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffFirstRunOptIn_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1119</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4131-9' platform='ie7' modified='2012-02-17'>
      <description>The "Web Browser Applications" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-286</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:242</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebBrowserApplications-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebBrowserApplications_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:242</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4013-9' platform='ie7' modified='2012-02-17'>
      <description>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1031</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:249, oval:org.mitre.oval:def:1393</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:249</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4153-3' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-200</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:621</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffFirst-RunOpt-In-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4052-7' platform='ie7' modified='2012-02-17'>
      <description>The "Web Browser Applications" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-51</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:580</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebBrowserApplications-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebBrowserApplications_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:580</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4175-6' platform='ie7' modified='2012-02-17'>
      <description>The "Intranet Sites: Include all network paths (UNCs)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-876</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:559, oval:org.mitre.oval:def:1370</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IncludeAllNetworkPaths-LocalComputer, IncludeAllNetworkPaths-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>include_all_network_paths_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:559</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3695-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Advanced Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\AdvancedTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-810</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:934, oval:org.mitre.oval:def:660</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableTheAdvancedPage-LocalComputer, DisableTheAdvancedPage-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3777-0' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Privacy Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\PrivacyTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-811</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1111</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableThePrivacyPage-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3433-0' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Security Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-595</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:672, oval:org.mitre.oval:def:601</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableTheSecurityPage-LocalComputer, DisableTheSecurityPage-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4199-6' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent Ignoing Certificate Errors" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\PreventIgnoreCertErrors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-938</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:655, oval:org.mitre.oval:def:1129</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventIgnoingCertificateErrors-LocalComputer, PreventIgnoingCertificateErrors-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>prevent_ignoring_certificate_errors_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:655</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3204-5' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Page</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-946</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:715</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffChangingURLDisplay-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffChangingURLDisplay_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:715</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4098-0' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off Configuring the Update Check Interval (In Days)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Interval</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-237</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1187</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffConfiguringUpdateCheckInterval-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffConfiguringUpdateCheckInterval_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1187</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3741-6' platform='ie7' modified='2012-02-17'>
      <description>The "Add-on List" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\ListBox_Support_CLSID</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-541</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:626</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AddOnList-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3997-4' platform='ie7' modified='2012-02-17'>
      <description>The "Deny all add-ons unless specifically allowed in the Add-on List" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\RestrictToList</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-911</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1278</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DenyAllAddOns-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4001-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable "Configuring History"" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\History</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-66</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:757, oval:org.mitre.oval:def:1365</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableConfiguringHistory-LocalComputer, DisableConfiguringHistory-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableConfiguringHistory_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:757</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4147-5' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Automatic Configuration Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Autoconfig</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-471</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1285, oval:org.mitre.oval:def:613</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingAutomaticConfigurationSettings-LocalComputer, DisableChangingAutomaticConfigurationSettings-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableChangingAutomaticConfigurationSettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1285</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4059-2' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Connection Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connection Settings</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-611</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:355, oval:org.mitre.oval:def:1128</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingConnectionSettings-LocalComputer, DisableChangingConnectionSettings-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3935-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Proxy Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Proxy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-62</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:398, oval:org.mitre.oval:def:635</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingProxySettings-LocalComputer, DisableChangingProxySettings-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3706-9' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Showing the Splash Screen" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSplash</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-556</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1164</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableShowingSplashScreen-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableShowingSplashScreen_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1164</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3975-0' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent "Fix settings" Functionality" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-948</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:448, oval:org.mitre.oval:def:640</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventFixSettingsFunctionality-LocalComputer, PreventFixSettingsFunctionality-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3993-3' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent participation in the Customer Experience Improvement Programs" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\SQM\DisableCustomerImprovementProgram</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-495</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1171, oval:org.mitre.oval:def:1391</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventParticipationInCustomerExperienceImprovementPrograms-LocalComputer, PreventParticipationInCustomerExperienceImprovementPrograms-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1171</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3207-8' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent performance of First Run Customize settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1006</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1322</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventPerformanceOfFirstRunCustomizeSettings-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1322</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4073-3' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent the deletation of temporary internet files and cookies" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-909</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1382, oval:org.mitre.oval:def:703</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PerventDeletationOfTempInternetFiles-LocalComputer, PerventDeletationOfTempInternetFiles-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3615-2' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off "Delete Browsing History" functionality" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteBrowsingHistory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1010</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:458, oval:org.mitre.oval:def:1474</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffDeleteBrowsingHistoryFunctionality-LocalComputer, TurnOffDeleteBrowsingHistoryFunctionality-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:458</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3866-1' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off Managing Phishing Filter" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\Enabled</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1032</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:501</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffManagingPhishingFilter-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffManagingPhishingFilter_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:501</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3875-2' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off the Security Settings Check feature" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1054</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:916, oval:org.mitre.oval:def:1034</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffSecuritySettingsCheckFeature-LocalComputer, TurnOffSecuritySettingsCheckFeature-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffSecuritySettingsCheckFeature_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:916</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4174-9' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Active Content from CD's to Run on User Machine" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCAL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-964</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:400</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowActiveContentFromCD-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowActiveContentFromCD_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:400</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4192-1' platform='ie7' modified='2012-02-17'>
      <description>The "Enable third-party browser extensions" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Enable Browser Extensions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-598</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:110</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowThird-PartyBrowserExtensions-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowThird-PartyBrowserExtensions_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:110</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3584-0' platform='ie7' modified='2012-02-17'>
      <description>The "Automatically Check for Internet Explorer Updates" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1008</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:656, oval:org.mitre.oval:def:1360</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AutomaticallyCheckIEUpdates-LocalComputer, AutomaticallyCheckForIEUpdates-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AutomaticallyCheckIEUpdates_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:656</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3976-8' platform='ie7' modified='2012-02-17'>
      <description>The "Check for Server Certificate Revocation" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-690</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:172, oval:org.mitre.oval:def:1502</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>CheckServerCertificateRevocation-LocalComputer, CheckForServerCertificateRevocation-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>CheckServerCertificateRevocation_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:172</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3853-9' platform='ie7' modified='2012-02-17'>
      <description>The "Access data sources across domains" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-47</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:674, oval:org.mitre.oval:def:650</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AccessDataSourcesAcrossDomains-InternetZone-LocalComputer, AccessDataSourcesAcrossDomains-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>access_data_sources_across_domains_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:674</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3998-2' platform='ie7' modified='2012-02-17'>
      <description>The "Drag and drop or copy and paste files" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1802</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-685</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1083, oval:org.mitre.oval:def:547</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowDragDropOrCopyPasteFiles-InternetZone-LocalComputer, AllowDragDropOrCopyPasteFiles-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1083</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3888-5' platform='ie7' modified='2012-02-17'>
      <description>The "Font download" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1604</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-491</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:524, oval:org.mitre.oval:def:659</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowFontDownloads-InternetZone-LocalComputer, AllowFontDownloads-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowFontDownloads_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:524</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3906-5' platform='ie7' modified='2012-02-17'>
      <description>The "Installation of desktop items" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1800</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-355</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:223, oval:org.mitre.oval:def:541</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowInstallationOfDesktopItems-InternetZone-LocalComputer, AllowInstallationOfDesktopItems-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowInstallationOfDesktopItems_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:223</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4099-8' platform='ie7' modified='2012-02-17'>
      <description>The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2102</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-280</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:589, oval:org.mitre.oval:def:1476</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalComputer, AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:589</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3601-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Scriptlets" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1209</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-439</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1043</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptlets-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_scriptlets_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1043</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3249-0' platform='ie7' modified='2012-02-17'>
      <description>The "Allow status bar updates via script" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-914</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:226, oval:org.mitre.oval:def:1208</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowStatusBarUpdatesViaScript-InternetZone-LocalComputer, AllowStatusBarUpdatesViaScript-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_status_bar_updates_via_script_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:226</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4139-2' platform='ie7' modified='2012-02-17'>
      <description>The "Automatic prompting for file downloads" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-16</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1113, oval:org.mitre.oval:def:562</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AutomaticPromptingFileDownloads-InternetZone-LocalComputer, AutomaticPromptingFileDownloads-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AutomaticPromptingFileDownloads_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1113</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3927-1' platform='ie7' modified='2012-02-17'>
      <description>The "Download signed ActiveX controls" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1013</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1199, oval:org.mitre.oval:def:546</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadSignedActiveXControls-InternetZone-LocalComputer, DownloadSignedActiveXControls-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>download_signed_activex_controls_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1199</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3945-3' platform='ie7' modified='2012-02-17'>
      <description>The "Download unsigned ActiveX controls" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-176</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:391, oval:org.mitre.oval:def:1200</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadUnsignedActiveXControls-InternetZone-LocalComputer, DownloadUnsignedActiveXControls-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DownloadUnsignedActiveXControls_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:391</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4068-3' platform='ie7' modified='2012-02-17'>
      <description>The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-586</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1040, oval:org.mitre.oval:def:739</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalComputer, JavaPermissions-InternetZone-LocalComputer, InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1040</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3963-6' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-132</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1174, oval:org.mitre.oval:def:725</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1174</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4104-6' platform='ie7' modified='2012-02-17'>
      <description>The "Launching programs and files in an IFRAME" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1804</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-689</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:611, oval:org.mitre.oval:def:1487</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalComputer, LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:611</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3623-6' platform='ie7' modified='2012-02-17'>
      <description>The "Logon" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current user name and password/Prompt for user name and password</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-720</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:691, oval:org.mitre.oval:def:1123</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LogonOptions-InternetZone-LocalComputer, LogonOptions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LogonOptions_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:691</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3751-5' platform='ie7' modified='2012-02-17'>
      <description>The "Loose XAML" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-126</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:240</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LooseXAMLFiles-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LooseXAMLFiles_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:240</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4143-4' platform='ie7' modified='2012-02-17'>
      <description>The "Navigate sub-frames across different domains" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1607</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-245</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:612, oval:org.mitre.oval:def:1394</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalComputer, NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>navigate_sub_frames_across_different_domains_Internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:612</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4161-6' platform='ie7' modified='2012-02-17'>
      <description>The "Open files based on content, not file extension" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-910</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:953, oval:org.mitre.oval:def:1300</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>OpenFilesBasedOnContent-InternetZone-LocalComputer, OpenFilesBasedOnContent-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>OpenFilesBasedOnContent_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:953</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3553-5' platform='ie7' modified='2012-02-17'>
      <description>The "Software channel permissions" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>High safety/low safety/medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-359</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:302, oval:org.mitre.oval:def:1398</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>SoftwareChannelPermissions-InternetZone-LocalComputer, SoftwareChannelPermissions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>SoftwareChannelPermissions_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:302</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3619-4' platform='ie7' modified='2012-02-17'>
      <description>The "Use Pop-up Blocker" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1809</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1002</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1179, oval:org.mitre.oval:def:558</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UsePop-upBlocker-InternetZone-LocalComputer, UsePop-upBlocker-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UsePop-upBlocker_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1179</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3914-9' platform='ie7' modified='2012-02-17'>
      <description>The "Userdata persistence" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1606</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-425</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1108</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UserdataPersistence-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UserdataPersistence_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3570-9' platform='ie7' modified='2012-02-17'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-724</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:265, oval:org.mitre.oval:def:1432</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalComputer, WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:265</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3843-0' platform='ie7' modified='2012-02-17'>
      <description>The "XPS documents" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2401</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1015</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:628</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>XPSFiles-InternetZone-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3984-2' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-878</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:245</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownInternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_locked_down_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:245</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3989-1' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-288</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1166</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-IntranetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_intranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1166</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4121-0' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Locked Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-552</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:247</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownIntranetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-LockedDownintranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:247</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4138-4' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-473</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:383</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-local_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:383</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4028-7' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Locked Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-239</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:418</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownLocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-LockedDownlocal_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:418</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3905-7' platform='ie7' modified='2012-02-17'>
      <description>The "Access data sources across domains" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      