Guidelines on Securing Public Web Servers
Securing backend servers that may support Web servers (e.g., database servers, file
servers)
Services other than Hypertext Transfer Protocol (HTTP) and Hypertext Transfer
Protocol Secure (HTTPS)
Protection of intellectual property.
Information on security related topics is available on NIST's Computer Security Resource
Center Web site (
http://csrc.nist.gov
).
1.3 Audience and Assumptions
The intended audience is varied. This document covers details specific to the various
components of Web content, Web applications, and Web servers. The document is technical
in nature; however, it provides the necessary background information to fully understand the
topics that are discussed.
Hence the following list highlights how people with differing backgrounds might use this
document:
System engineers and architects when designing and implementing Web servers
Web and system administrators when administering, patching, securing, or upgrading
Web servers
Webmasters when creating and managing Web content
Security consultants when performing security audits to determine information system
(IS) security postures
Program managers and information systems security officers (ISSO) to ensure that
adequate security measures have been considered for all aspects of Web server
operations.
This document assumes that readers have some minimal operating system, networking, and
Web server expertise. Because of the constantly changing nature of the Web server threats and
vulnerabilities, readers are expected to take advantage of other resources (including those listed
in this document) for more current and detailed information.
1.4 Document
Structure
The document is divided into eight sections followed by six appendixes. This subsection is a
roadmap describing the structure.
Section 1 (this section) provides an authority, purpose and scope, audience and
assumptions, and document structure.
5
Although this document does not address the specific security concerns that arise from high traffic multiple server
Web farms, much of what is covered will apply to these types of installations.
2