Guidelines on Securing Public Web Servers
Step 7. Conducting initial and periodic vulnerability scans of each public Web server
and supporting network infrastructure (e.g., firewalls, routers).
The practices recommended in this document are designed to help mitigate the risks associated
with public Web servers. They build on and assume the implementation of practices described
in the following NIST guidelines as appropriate:
NIST Special Publication 800 3,
Establishing a Computer Security Incident Response
Capability
NIST Special Publication 800 18,
Guide to Developing Security Plans for
Information Technology Systems
NIST Special Publication 800 26,
Security Self Assessment Guide for Information
Technology Systems
NIST Special Publication 800 27,
Engineering Principles for Information Technology
Security
NIST Special Publication 800 28,
Guidelines on Active Content and Mobile Code
NIST Special Publication 800 31,
Intrusion Detection Systems
NIST Special Publication 800 32,
Introduction to Public Key Technology and the
Federal PKI Infrastructure
NIST Special Publication 800 34,
Contingency Planning Guide for Information
Technology Systems
NIST Special Publication 800 37,
Federal Guidelines for the Security Certification
and Accreditation of Information Technology Systems
NIST Special Publication 800 40,
Procedures for Handling Security Patches
NIST Special Publication 800 41,
Guide to Firewall Selection and Policy
Recommendation
s
NIST Special Publication 800 42,
Guideline on Network Security Testing
NIST Special Publication 800 43,
Guide to Securing Windows 2000 Professional
NIST Special Publication 800 46,
Security for Telecommuting and Broadband
Communications
NIST Special Publication 800 52,
Guidelines for the Selection and Use of Transport
Layer Security Implementations.
All these guidelines and others can be found at the NIST Computer Security Resource Web
site at
http://csrc.nist.gov/publications/nistpubs/index.html
.
6
Unlimited Web Hosting
|
|
TotalRoute.net Business web hosting division of Vision Web Hosting Inc. All rights reserved. |