Product:
BigFix Compliance
Title:
Updated DISA Checklist for Apache Server 2_4 on Windows to support a more recent version of the benchmark
Security Benchmark:
DISA STIG Apache Server 2.4 Windows Site_V2R3 Server_V3R4
Published Sites:
DISA STIG Checklist for Apache Server 2.4 on Windows, site version 17
(The site version is provided for air-gap customers.)
Details:
Total New Fixlets: 1
Total Updated Fixlets:3
Total Deleted Fixlets: 23
Total Fixlets in Site: 35
- New Fixlets
- V-214328
Updated Fixlets
V-214308
V-214311
V-214338
Deleted Fixlets
V-214331, V-214334, V-214354, V-214358, V-214362, V-214363, V-214364,
V-214366, V-214369, V-214370, V-214375, V-214377, V-214378, V-214379,
V-214381, V-214384, V-214385, V-214386, V-214387, V-214392, V-214393,
V-214396, V-214397
The Environment Setup task utilizes atomic result refreshes, ensuring that existing results remain available until new results are generated. Results now also include a collection timestamp for better tracking and auditability
The checklist now evaluates compliance using a dynamically generated merged configuration file. During execution, it automatically identifies the primary configuration files, processes all included configuration files, and creates a consolidated configuration view. Compliance checks are then performed against this merged configuration, ensuring a more accurate and comprehensive assessment of the effective server configuration.
The Applicability Fixlet verifies that the Environment Setup Task log file exists, is not older than 90 days, and that the required result files are present. This ensures that Fixlets are reported as Not Applicable when the Environment Setup Task has not been executed, and that the Measured Value (MV) correctly reflects this condition.
Some of the checks allow you to use the parameterized setting to enable customization for compliance evaluation. Note that parameterization and remediation actions require the creation of a custom site.
Actions to take:
To subscribe to the above site, you can use the License Overview Dashboard to enable and gather the site. Note that you must be entitled to the BigFix Compliance product, and you must be using BigFix version 10 and later.
If you use custom sites, update your custom sites accordingly to use the latest content. You can synchronize your content by using the Synchronize Custom Checks wizard. For more information, see
More information:
To know more about the BigFix Compliance SCM checklists, please see the following resources:
BigFix Forum:
BigFix Compliance SCM Checklists:
We hope you find this latest release of SCM content useful and effective. Thank you!
– The BigFix Compliance team