Akamai KSD Service Impact Level 2 ALG Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
Digest of Updates +33 −33
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 33
- V-237104 High Kona Site Defender must immediately use updates made to policy enforcement mechanisms to enforce that all traffic flows over HTTPS port 443.
- V-237105 High Kona Site Defender must immediately apply updates to the Kona Rule Set to block designated traffic of interest in response to new or emerging threats.
- V-237106 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to block traffic from organizationally defined geographic regions.
- V-237107 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to block traffic from organizationally defined IP addresses (i.e., IP blacklist).
- V-237108 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to allow traffic from organizationally defined IP addresses (i.e., IP whitelist).
- V-237109 High Kona Site Defender that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.
- V-237110 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent code injection attacks from being launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
- V-237111 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.
- V-237112 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
- V-237113 Medium To protect against data mining, Kona Site Defender providing content filtering must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
- V-237114 Medium To protect against data mining, Kona Site Defender providing content filtering must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
- V-237115 Medium To protect against data mining, Kona Site Defender providing content filtering as part of its intermediary services must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.
- V-237116 Medium Kona Site Defender must off-load audit records onto a centralized log server.
- V-237117 Low Kona Site Defender must off-load audit records onto a centralized log server in real time.
- V-237118 Medium Kona Site Defender must not strip origin-defined HTTP session headers.
- V-237119 Medium Kona Site Defender providing content filtering must protect against known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis.
- V-237120 Medium Kona Site Defender providing content filtering must protect against known types of denial-of-service (DoS) attacks by employing signatures.
- V-237121 Medium Kona Site Defender that provides intermediary services for HTTP must inspect inbound and outbound HTTP traffic for protocol compliance and protocol anomalies.
- V-237122 High Kona Site Defender providing encryption intermediary services must implement NIST FIPS-validated cryptography to generate cryptographic hashes.
- V-237123 Medium Kona Site Defender providing encryption intermediary services must implement NIST FIPS-validated cryptography for digital signatures.
- V-237124 High Kona Site Defender providing encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services.
- V-237125 High Kona Site Defender providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoW PKI or DoW-approved PKI Certification Authorities (CAs) for the establishment of protected sessions.
- V-237126 Medium Kona Site Defender providing content filtering must update malicious code protection mechanisms and signature definitions whenever new releases are available in accordance with organizational configuration management policy and procedures.
- V-237127 Medium Kona Site Defender providing content filtering must block malicious code upon detection.
- V-237128 Medium Kona Site Defender providing content filtering must send an immediate (within seconds) alert to the system administrator, at a minimum, in response to malicious code detection.
- V-237129 Low Kona Site Defender providing content filtering must be configured to integrate with a system-wide intrusion detection system.
- V-237130 Medium Kona Site Defender providing content filtering must continuously monitor inbound communications traffic crossing internal security boundaries for unusual or unauthorized activities or conditions.
- V-237131 Medium Kona Site Defender providing content filtering must send an alert to, at a minimum, the ISSO and ISSM when detection events occur.
- V-237132 Medium Kona Site Defender providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected.
- V-237133 Medium Kona Site Defender providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when denial-of-service (DoS) incidents are detected.
- V-237134 Medium Kona Site Defender must check the validity of all data inputs except those specifically identified by the organization.
- V-237135 High Kona Site Defender must reveal error messages only to the ISSO, ISSM, and SCA.
- V-237136 Medium Kona Site Defender must only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.
Removed rules 33
- V-76391 High Kona Site Defender must immediately use updates made to policy enforcement mechanisms to enforce that all traffic flows over HTTPS port 443.
- V-76393 High Kona Site Defender must immediately apply updates to the Kona Rule Set to block designated traffic of interest in response to new or emerging threats.
- V-76395 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to block traffic from organizationally defined geographic regions.
- V-76397 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to block traffic from organizationally defined IP addresses (i.e., IP blacklist).
- V-76399 Medium Kona Site Defender must immediately use updates made to policy enforcement mechanisms to allow traffic from organizationally defined IP addresses (i.e., IP whitelist).
- V-76401 High Kona Site Defender that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.
- V-76403 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent code injection attacks from being launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
- V-76405 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.
- V-76407 Medium To protect against data mining, Kona Site Defender providing content filtering must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
- V-76409 Medium To protect against data mining, Kona Site Defender providing content filtering must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
- V-76411 Medium To protect against data mining, Kona Site Defender providing content filtering must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
- V-76413 Medium To protect against data mining, Kona Site Defender providing content filtering as part of its intermediary services must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.
- V-76415 Medium Kona Site Defender must off-load audit records onto a centralized log server.
- V-76417 Low Kona Site Defender must off-load audit records onto a centralized log server in real time.
- V-76419 Medium Kona Site Defender must not strip origin-defined HTTP session headers.
- V-76421 Medium Kona Site Defender providing content filtering must protect against known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis.
- V-76423 Medium Kona Site Defender providing content filtering must protect against known types of denial-of-service (DoS) attacks by employing signatures.
- V-76425 Medium Kona Site Defender that provides intermediary services for HTTP must inspect inbound and outbound HTTP traffic for protocol compliance and protocol anomalies.
- V-76427 High Kona Site Defender providing encryption intermediary services must implement NIST FIPS-validated cryptography to generate cryptographic hashes.
- V-76429 Medium Kona Site Defender providing encryption intermediary services must implement NIST FIPS-validated cryptography for digital signatures.
- V-76431 High Kona Site Defender providing encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services.
- V-76433 High Kona Site Defender providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of protected sessions.
- V-76435 Medium Kona Site Defender providing content filtering must update malicious code protection mechanisms and signature definitions whenever new releases are available in accordance with organizational configuration management policy and procedures.
- V-76437 Medium Kona Site Defender providing content filtering must block malicious code upon detection.
- V-76439 Medium Kona Site Defender providing content filtering must send an immediate (within seconds) alert to the system administrator, at a minimum, in response to malicious code detection.
- V-76441 Low Kona Site Defender providing content filtering must be configured to integrate with a system-wide intrusion detection system.
- V-76443 Medium Kona Site Defender providing content filtering must continuously monitor inbound communications traffic crossing internal security boundaries for unusual or unauthorized activities or conditions.
- V-76445 Medium Kona Site Defender providing content filtering must send an alert to, at a minimum, the ISSO and ISSM when detection events occur.
- V-76447 Medium Kona Site Defender providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected.
- V-76449 Medium Kona Site Defender providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when denial-of-service (DoS) incidents are detected.
- V-76451 Medium Kona Site Defender must check the validity of all data inputs except those specifically identified by the organization.
- V-76453 High Kona Site Defender must reveal error messages only to the ISSO, ISSM, and SCA.
- V-76455 Medium Kona Site Defender must only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001414
- Version
- AKSD-WF-000001
- Vuln IDs
-
- V-237104
- V-76391
- Rule IDs
-
- SV-237104r1137546_rule
- SV-91087
Checks: C-40323r640485_chk
Confirm Kona Site Defender is configured to enforce all traffic flows over HTTPS port 443: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. In the "Property Version Information" section, verify the "Security Options" check box is checked. If the "Security Options" check box in "Property Manager" is not configured to enforce all traffic flows over HTTPS port 443, this is a finding.
Fix: F-40286r640486_fix
Configure Kona Site Defender to enforce all traffic flows over HTTPS port 443: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. On the "Property Manager Editor" screen, click the "Edit New Version" button. 6. In the "Property Version Information" section, enable the "Security Options" check box. 7. Click the "Save" button. 8. Select the "Activate" tab and push the configuration to production.
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001414
- Version
- AKSD-WF-000002
- Vuln IDs
-
- V-237105
- V-76393
- Rule IDs
-
- SV-237105r1137547_rule
- SV-91089
Checks: C-40324r640488_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40287r640489_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- AKSD-WF-000003
- Vuln IDs
-
- V-237106
- V-76395
- Rule IDs
-
- SV-237106r1137547_rule
- SV-91091
Checks: C-40325r640491_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined geographic regions: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Network Layer Controls" checkbox is enabled. 9. Within the "Network Layer Controls Configuration" section, verify the organizationally defined geographic regions appear in the "Blocked GEOs" list. If the Network Layer Controls are not enabled and the organizationally defined geographic regions do not appear in the list, this is a finding.
Fix: F-40288r640492_fix
Configure the Kona Site Defender to block traffic for organizationally defined geographic regions: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed, click the "Edit" button, and enable the "Network Layer Controls" box. 8. Select the "Geographical Controls" tab and add the blocked geographic regions. 9. Click the "Save" button and the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- AKSD-WF-000004
- Vuln IDs
-
- V-237107
- V-76397
- Rule IDs
-
- SV-237107r1137547_rule
- SV-91093
Checks: C-40326r640494_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined IP addresses: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Network Layer Controls" checkbox is enabled. 9. Within the "Network Layer Controls Configuration" section, verify the organizationally defined IP address appear in the "Blocked IPs" area, and the applicable predefined network lists appear in the "Blocked IP Network Lists" area. If the Network Layer Controls are not enabled and the organizationally defined IP addresses/network lists do not appear in the lists area, this is a finding.
Fix: F-40289r640495_fix
Configure the Kona Site Defender to block traffic for organizationally defined IP addresses: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" sections, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed, click the "Edit" button, and enable the "Network Layer Controls" box. 8. Select the "IP Controls" tab and add the blocked IP addresses. 9. Select the "Network Lists" tab and add/select the blocked network lists. 10. Click the "Save" button and the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- AKSD-WF-000005
- Vuln IDs
-
- V-237108
- V-76399
- Rule IDs
-
- SV-237108r1137547_rule
- SV-91095
Checks: C-40327r640497_chk
Confirm Kona Site Defender is configured to allow traffic for organizationally defined IP addresses: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Network Layer Controls" checkbox is enabled. 9. Within the "Network Layer Controls Configuration" section, verify the organizationally defined IP addresses appear in the "Allowed IPs" area and the applicable predefined network lists appear in the "Allowed IP Network Lists" area. If the Network Layer Controls are not enabled and the organizationally defined IP addresses/network lists do not appear in the lists area, this is a finding. NOTE: Not all sites will implement organizationally defined white lists.
Fix: F-40290r640498_fix
Configure the Kona Site Defender to allow traffic for organizationally defined IP addresses: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" sections, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed, click the "Edit" button, and enable the "Network Layer Controls" box. 8. Select the "IP Controls" tab and add the blocked IP addresses to the "Allowed IPs" area. 9. Select the "Network Lists" tab and add/select the allowed network lists to the "Reputation Whitelist" area. 10. Click the "Save" button and the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- AKSD-WF-000007
- Vuln IDs
-
- V-237109
- V-76401
- Rule IDs
-
- SV-237109r1267981_rule
- SV-91097
Checks: C-40328r640500_chk
Confirm Kona Site Defender allows only NIST SP 800-52 TLS settings: 1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html 2. Enter into the scanner the Hostname being tested. 3. Under the "Configurations" and then "Protocol" section, verify that communications are restricted to TLS versions 1.2 and above for government-only services or TLS versions 1.0 and above for citizen or business-facing applications. If Kona Site Defender does not allow only NIST SP 800-52 TLS settings, this is a finding.
Fix: F-40291r640501_fix
Configure Kona Site Defender to only allow NIST SP 800-52 TLS settings: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- AKSD-WF-000009
- Vuln IDs
-
- V-237110
- V-76403
- Rule IDs
-
- SV-237110r831334_rule
- SV-91099
Checks: C-40329r640503_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40292r640504_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- AKSD-WF-000010
- Vuln IDs
-
- V-237111
- V-76405
- Rule IDs
-
- SV-237111r831335_rule
- SV-91101
Checks: C-40330r640506_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40293r640507_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- AKSD-WF-000011
- Vuln IDs
-
- V-237112
- V-76407
- Rule IDs
-
- SV-237112r831336_rule
- SV-91103
Checks: C-40331r640509_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40294r640510_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- AKSD-WF-000012
- Vuln IDs
-
- V-237113
- V-76409
- Rule IDs
-
- SV-237113r831337_rule
- SV-91105
Checks: C-40332r640512_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40295r640513_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- AKSD-WF-000013
- Vuln IDs
-
- V-237114
- V-76411
- Rule IDs
-
- SV-237114r831338_rule
- SV-91107
Checks: C-40333r640515_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40296r640516_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- AKSD-WF-000014
- Vuln IDs
-
- V-237115
- V-76413
- Rule IDs
-
- SV-237115r831339_rule
- SV-91109
Checks: C-40334r640518_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40297r640519_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- AKSD-WF-000015
- Vuln IDs
-
- V-237116
- V-76415
- Rule IDs
-
- SV-237116r831340_rule
- SV-91111
Checks: C-40335r640521_chk
Confirm Kona Site Defender is configured to deliver web logs via the Log Delivery Service (LDS): 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. Under the "Log Request Details" section, verify that "Log Host Header", "Log Referrer Header", and "Log User-Agent Header" are all enabled. 6. Under the "Log Request Details" section, confirm that "Cookie Mode" is set to "Log all cookies" or "Log some cookies" with the applicable cookies specified in the box below. 7. Click the "Configure" tab. 8. Select "Log Delivery". 9. Verify the status is "Active" for the applicable object ID. If log delivery is not configured properly, this is a finding.
Fix: F-40298r640522_fix
Configure Kona Site Defender to deliver web logs via the Log Delivery Service (LDS): 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. Click the "Edit" button (if not already selected). 6. Under the "Log Request Details" section, enable "Log Host Header", "Log Referrer Header", and "Log User-Agent Header". 7. Under the "Log Request Details" section, set "Cookie Mode" is set to "Log all cookies" or "Log some cookies" with the applicable cookies specified in the box below. 8. Click the "Save" button. 9. Activate the configuration by clicking the "Activate" tab and the activate buttons for the proper network (either staging or production). 10. Once the configuration has been propagated to the proper network, click the "Configure" tab. 11. Select "Log Delivery". 12. In the same row as the applicable object ID, click the gear icon under the "Action" column. 13. Select "Begin Log Delivery" and then either "New" or ""Copy" 14. Proceed through the prompts to select the log format and location to send the logs.
- RMF Control
- AU-4
- Severity
- L
- CCI
- CCI-001851
- Version
- AKSD-WF-000016
- Vuln IDs
-
- V-237117
- V-76417
- Rule IDs
-
- SV-237117r1267982_rule
- SV-91113
Checks: C-40336r640524_chk
If the SIEM delivery option has been purchased, confirm that the Kona Site Defender SIEM integration is enabled: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted, select "Site Defender" and then "Continue". 5. Open the security configuration for which SIEM data is required. 6. Scroll down to the SIEM Integration section and verify that "Allow data collection for SIEM" is enabled. If "Allow data collection for SIEM field" is not enabled, this is a finding.
Fix: F-40299r640525_fix
Configure Kona Site Defender to deliver security event traffic to the SIEM: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted, select the product with which you would like to work and click "Continue". 5. Open the security configuration for which you want SIEM data. 6. Scroll down to the SIEM Integration section. 7. In the "Allow data collection for SIEM" field, click "Yes". 8. Choose the firewall policies for which you want to export data. Enable SIEM integration for: - ALL Firewall policies if you want to send SIEM data for events that violate any/all firewall policies within the security configuration. - The following firewall policies if you want data regarding one or more specific firewall policies. In the drop down list, choose the policies you want. 9. Skip the SIEM Event Version field for now. 10. Copy the number in the Security Config ID field. You’ll need it in a minute. 11. Push security configuration changes to the production network. - On the upper right of the Security Configuration page, click the Activate button. Under Network, choose Production and click Activate
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- AKSD-WF-000018
- Vuln IDs
-
- V-237118
- V-76419
- Rule IDs
-
- SV-237118r640529_rule
- SV-91115
Checks: C-40337r640527_chk
Confirm Kona Site Defender is not stripping origin-defined HTTP session headers: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Configure" tab and select "Site" under the "Property" section. 3. If prompted for which product to use, select "Site Defender" and then "Continue". 4. Click on the applicable configuration. 5. Click on the applicable version of the configuration. 6. Click the "View XML" button. 7. Search the XML text for the following fields and confirm that no origin session headers are being added or removed: "edgeservices:modify-incoming-request.remove-header" "edgeservices:modify-incoming-request.add-header" "edgeservices:modify-incoming-response.remove-header" "edgeservices:modify-incoming-response.add-header" "edgeservices:modify-outgoing-request.remove-header" "edgeservices:modify-outgoing-request.add-header" "edgeservices:modify-outgoing-response.remove-header" "edgeservices:modify-outgoing-response.add-header" If Kona Site Defender is stripping origin-defined HTTP session headers, this is a finding.
Fix: F-40300r640528_fix
Configure Kona Site Defender to not modify origin-defined HTTP session headers: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Configure" tab and select "Site" under the "Property" section. 3. If prompted for which product to use, select "Site Defender" and then "Continue". 4. Click on the applicable configuration. 5. Click on the applicable version of the configuration. 6. Search the "Property Configuration Settings" and remove any of the following behaviors that are modifying origin-defined HTTP session headers: "Modify Incoming Request Header" "Modify Incoming Response Header" "Modify Outgoing Request Header" "Modify Outgoing Response Header" OR Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- AKSD-WF-000019
- Vuln IDs
-
- V-237119
- V-76421
- Rule IDs
-
- SV-237119r831342_rule
- SV-91117
Checks: C-40338r640530_chk
Confirm Kona Site Defender has rate controls enabled: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Within the "Policy Details" section, verify the "Rate Controls" check box is selected. 9. Within the "Rate Controls" section, verify the action is set to "Deny" for each Adaptive Rule ID. If "Rate Controls" is not selected, this is a finding.
Fix: F-40301r640531_fix
Configure the Kona Site Defender to enable rate controls. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Click on the "Shared Resources" link. 8. Click on the "Rate Policies" link in the left hand column. 9. Click the plus shaped "+" icon to add a new Rate Policy. 10. Follow the prompts to complete the process and click the "Save" button to complete the process. OR Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- AKSD-WF-000020
- Vuln IDs
-
- V-237120
- V-76423
- Rule IDs
-
- SV-237120r831343_rule
- SV-91119
Checks: C-40339r640533_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40302r640534_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AKSD-WF-000021
- Vuln IDs
-
- V-237121
- V-76425
- Rule IDs
-
- SV-237121r640538_rule
- SV-91121
Checks: C-40340r640536_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40303r640537_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- AKSD-WF-000022
- Vuln IDs
-
- V-237122
- V-76427
- Rule IDs
-
- SV-237122r1137559_rule
- SV-91123
Checks: C-40341r640539_chk
Confirm Kona Site Defender only allows NIST SP 800-52 TLS settings: 1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html 2. Enter into the scanner the Hostname being tested. 3. Under the "Configurations" and then "Cipher Suites" section, verify that communications are restricted to NIST FIPS-validated cryptography to generate cryptographic hashes as defined at https://www.nist.gov/publications/guidelines-selection-configuration-and-use-transport-layer-security-tls-implementations?pub_id=915295. If the cipher suites include non-NIST FIPS-validated cryptography, this is a finding.
Fix: F-40304r640540_fix
Configure Kona Site Defender to only allow NIST FIPS-validated cryptography to generate cryptographic hashes: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- AKSD-WF-000023
- Vuln IDs
-
- V-237123
- V-76429
- Rule IDs
-
- SV-237123r1137560_rule
- SV-91125
Checks: C-40342r640542_chk
Confirm Kona Site Defender only allows NIST SP 800-52 TLS settings: 1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html 2. Enter into the scanner the Hostname being tested. 3. Under the "Certificate" section, verify that the "Signature algorithm" is restricted to NIST FIPS-validated cryptography for digital signatures as defined at https://www.nist.gov/publications/guidelines-selection-configuration-and-use-transport-layer-security-tls-implementations?pub_id=915295. If the signature algorithm include non-NIST FIPS-validated cryptography, this is a finding.
Fix: F-40305r640543_fix
Configure Kona Site Defender to only allow NIST FIPS-validated cryptography for digital signatures: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- AKSD-WF-000024
- Vuln IDs
-
- V-237124
- V-76431
- Rule IDs
-
- SV-237124r1137561_rule
- SV-91127
Checks: C-40343r640545_chk
Confirm Kona Site Defender only allows NIST SP 800-52 TLS settings: 1. Navigate to the Qualys SSL Scanner: https://www.ssllabs.com/ssltest/analyze.html 2. Enter into the scanner the Hostname being tested. 3. Under the "Configurations" and then "Cipher Suites" section, verify that communications are restricted to NIST FIPS-validated cryptography to implement encryption services as defined at https://www.nist.gov/publications/guidelines-selection-configuration-and-use-transport-layer-security-tls-implementations?pub_id=915295. If the cipher suites include non-NIST FIPS-validated cryptography, this is a finding.
Fix: F-40306r640546_fix
Configure Kona Site Defender to only allow NIST FIPS-validated cryptography to implement encryption services: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SC-23
- Severity
- H
- CCI
- CCI-002470
- Version
- AKSD-WF-000025
- Vuln IDs
-
- V-237125
- V-76433
- Rule IDs
-
- SV-237125r1267985_rule
- SV-91129
Checks: C-40344r1267983_chk
If Kona Site Defender is providing user authentication intermediary services, confirm that it accepts only end entity certificates issued by DoW PKI or DoW-approved PKI CAs for the establishment of protected sessions: Contact the Akamai Professional Services team to confirm accepted certificate authorities at 1-877-4-AKATEC (1-877-425-2832). If the Akamai Professional Services team confirms that the list of accepted certificate authorities is not issued by DoW-approved PKI certification authorities, this is a finding.
Fix: F-40307r1267984_fix
Configure Kona Site Defender to accept only end entity certificates issued by DoW PKI or DoW-approved PKI CAs for the establishment of protected sessions: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001240
- Version
- AKSD-WF-000026
- Vuln IDs
-
- V-237126
- V-76435
- Rule IDs
-
- SV-237126r981632_rule
- SV-91131
Checks: C-40345r640551_chk
Confirm Kona Site Defender is configured to use the latest rule set to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. For the applicable security configuration, click on the tuning status details link under the "Tuning Status" column. If the tuning status does not state "You are using the latest Kona Rule Set version and your security configuration is optimal", this is a finding.
Fix: F-40308r640552_fix
Configure Kona Site Defender to use the latest rule set to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: Contact the Akamai Professional Services team to implement the changes at 1-877-4-AKATEC (1-877-425-2832).
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- AKSD-WF-000028
- Vuln IDs
-
- V-237127
- V-76437
- Rule IDs
-
- SV-237127r640556_rule
- SV-91133
Checks: C-40346r640554_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40309r640555_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- AKSD-WF-000030
- Vuln IDs
-
- V-237128
- V-76439
- Rule IDs
-
- SV-237128r640559_rule
- SV-91135
Checks: C-40347r640557_chk
Confirm Kona Site Defender is configured to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Confirm that notifications are being sent when "Mitigated" is greater than (>) "1". If the alerts are not being sent, this is a finding.
Fix: F-40310r640558_fix
Configure Kona Site Defender to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Click the "Add Notification" button shaped like a plus sign. 7. Click the "Show Advanced View" link. 8. Set the "Notification Name" to "WAF Activity Mitigated" 9. Enter a more detailed description in the “Description” text box. 10. Set the priority to "high". 11. In the "Notify When:" section, set "Mitigated" to greater than (>) 1. 12. Set the “Apply Filter:” dropdowns to “Host Name” and “Contains”, and enter the applicable host name in the text box. 13. Set "During:" to "1 Minute". 14. Set "Notify After:" to "1" occurrences. 15. Select the "Host Name" check box in the "For:" area. 16. Add the ISSO and ISSM emails to the "Email to:" field. 17. Click the “Save” button.
- RMF Control
- SI-4
- Severity
- L
- CCI
- CCI-002656
- Version
- AKSD-WF-000032
- Vuln IDs
-
- V-237129
- V-76441
- Rule IDs
-
- SV-237129r831348_rule
- SV-91137
Checks: C-40348r640560_chk
If the SIEM delivery option has been purchased, confirm that the Kona Site Defender SIEM integration is enabled: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted, select "Site Defender" and then "Continue". 5. Open the security configuration for which SIEM data is required. 6. Scroll down to the SIEM Integration section and verify that "Allow data collection for SIEM" is enabled. If "Allow data collection for SIEM field" is not enabled, this is a finding.
Fix: F-40311r640561_fix
Configure Kona Site Defender to deliver security event traffic to the SIEM: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted, select the product with which you would like to work and click "Continue". 5. Open the security configuration for which you want SIEM data. 6. Scroll down to the SIEM Integration section. 7. In the "Allow data collection for SIEM" field, click "Yes". 8. Choose the firewall policies for which you want to export data. Enable SIEM integration for: - ALL Firewall policies if you want to send SIEM data for events that violate any/all firewall policies within the security configuration. - The following firewall policies if you want data regarding one or more specific firewall policies. In the drop down list, choose the policies you want. 9. Skip the SIEM Event Version field for now. 10. Copy the number in the Security Config ID field. You’ll need it in a minute. 11. Push security configuration changes to the production network. - On the upper right of the Security Configuration page, click the Activate button. Under Network, choose Production and click Activate
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002661
- Version
- AKSD-WF-000033
- Vuln IDs
-
- V-237130
- V-76443
- Rule IDs
-
- SV-237130r831349_rule
- SV-91139
Checks: C-40349r640563_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40312r640564_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- AKSD-WF-000034
- Vuln IDs
-
- V-237131
- V-76445
- Rule IDs
-
- SV-237131r971533_rule
- SV-91141
Checks: C-40350r640566_chk
Confirm Kona Site Defender is configured to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Confirm that notifications are being sent when "Mitigated" is greater than (>) "1". If the alerts are not being sent, this is a finding.
Fix: F-40313r640567_fix
Configure Kona Site Defender to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Click the "Add Notification" button shaped like a plus sign. 7. Click the "Show Advanced View" link. 8. Set the "Notification Name" to "WAF Activity Mitigated" 9. Enter a more detailed description in the “Description” text box. 10. Set the priority to "high". 11. In the "Notify When:" section, set "Mitigated" to greater than (>) 1. 12. Set the “Apply Filter:” dropdowns to “Host Name” and “Contains”, and enter the applicable host name in the text box. 13. Set "During:" to "1 Minute". 14. Set "Notify After:" to "1" occurrences. 15. Select the "Host Name" check box in the "For:" area. 16. Add the ISSO and ISSM emails to the "Email to:" field. 17. Click the “Save” button.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- AKSD-WF-000035
- Vuln IDs
-
- V-237132
- V-76447
- Rule IDs
-
- SV-237132r971533_rule
- SV-91143
Checks: C-40351r640569_chk
Confirm Kona Site Defender is configured to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Confirm that notifications are being sent when "Mitigated" is greater than (>) "1". If the alerts are not being sent, this is a finding.
Fix: F-40314r640570_fix
Configure Kona Site Defender to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Click the "Add Notification" button shaped like a plus sign. 7. Click the "Show Advanced View" link. 8. Set the "Notification Name" to "WAF Activity Mitigated" 9. Enter a more detailed description in the “Description” text box. 10. Set the priority to "high". 11. In the "Notify When:" section, set "Mitigated" to greater than (>) "1". 12. Set the “Apply Filter:” dropdowns to “Host Name” and “Contains”, and enter the applicable host name in the text box. 13. Set "During:" to "1 Minute". 14. Set "Notify After:" to "1" occurrences. 15. Select the "Host Name" check box in the "For:" area. 16. Add the ISSO and ISSM emails to the "Email to:" field. 17. Click the “Save” button.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- AKSD-WF-000036
- Vuln IDs
-
- V-237133
- V-76449
- Rule IDs
-
- SV-237133r1267986_rule
- SV-91145
Checks: C-40352r640572_chk
Confirm Kona Site Defender is configured to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Confirm that notifications are being sent when "Mitigated" is greater than (>) "1". If the alerts are not being sent, this is a finding.
Fix: F-40315r640573_fix
Configure Kona Site Defender to alert the ISSO, ISSM, and SA when detection events occur: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Monitor" tab. 3. Under the "Security" section select "Security Monitor". 4. Click the "Notification" button (an icon shaped like a triangle with an exclamation point on the inside) 5. Click the "Configure Notification" button shaped like a plus sign. 6. Click the "Add Notification" button shaped like a plus sign. 7. Click the "Show Advanced View" link. 8. Set the "Notification Name" to "WAF Activity Mitigated" 9. Enter a more detailed description in the “Description” text box. 10. Set the priority to "high". 11. In the "Notify When:" section, set "Mitigated" to greater than (>) "1". 12. Set the “Apply Filter:” dropdowns to “Host Name” and “Contains”, and enter the applicable host name in the text box. 13. Set "During:" to "1 Minute". 14. Set "Notify After:" to "1" occurrences. 15. Select the "Host Name" check box in the "For:" area. 16. Add the ISSO and ISSM emails to the "Email to:" field. 17. Click the “Save” button.
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-001310
- Version
- AKSD-WF-000037
- Vuln IDs
-
- V-237134
- V-76451
- Rule IDs
-
- SV-237134r640577_rule
- SV-91147
Checks: C-40353r640575_chk
Confirm Kona Site Defender is configured to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules: 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed. 8. Verify the "Application Layer Controls" checkbox is enabled. 9. Verify the following "KRS Rule Set" rules are set to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Scor4e (Inbound) - Total Response Score (Outbound) - DDOS 10. Verify the "Enabled Slow POST Protection" section appears. If the application layer controls are not set to "Deny" mode or slow POST protection does not appear, this is a finding.
Fix: F-40316r640576_fix
Configure the Kona Site Defender to block traffic for organizationally defined HTTP protocol violations, HTTP policy violations, SQL injection, remote file inclusion, cross-site scripting, command injection attacks, and any applicable custom rules. The Akamai Professional Services team should be consulted to implement this Fix content due to the complexities involved. In most cases, this should be included in the SLA. 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Click the "Configure" tab. 3. Under the "Security" section, select "Security Configuration". 4. If prompted for which product to use, select "Site Defender" and then "Continue". 5. Under the "Security Configurations" section, click on the most recent version under the "Production" column for the security configuration being reviewed. 6. The detailed "Security Configuration" page will load listing the protected host names and applicable policies. 7. Select the policy being reviewed and click the "Edit" button. 8. Enable the "Application Layer Controls" box and the "Slow POST Protection" box. 9. Click the "Next" button and set each of the following "KRS Rule Set" rules to "Deny". - SQL Injection - Cross Site Scripting (XSS) - Command Injection - Invalid HTTP - Remote File Inclusion - PHP Injection (when PHP is used) - Trojan - Total Request Score (Inbound) - Total Response Score (Outbound) - DDOS 10. Click the "Next" button and follow the prompts to complete the process.
- RMF Control
- SI-11
- Severity
- H
- CCI
- CCI-001314
- Version
- AKSD-WF-000039
- Vuln IDs
-
- V-237135
- V-76453
- Rule IDs
-
- SV-237135r640580_rule
- SV-91149
Checks: C-40354r640578_chk
Verify that only authorized personnel have access to the Kona Site Defender portal (Luna): 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Select "Configure" and then "Manage Users & Groups". 3. Select the "Roles" tab. 4. Review the personnel list and their current roles. If non-privileged users can perform privileged functions, this is a finding.
Fix: F-40317r640579_fix
Ensure that only authorized personnel have access to the Kona Site Defender portal (Luna): 1. Log in to the Akamai Luna Portal (https://control.akamai.com). 2. Select "Configure" and then "Manage Users & Groups". 3. Select the "Users" tab. 4. Add the correct personnel by clicking the "Create a New User" button or remove existing users by clicking the gear icon next to their entry and selecting "Delete this user".
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002403
- Version
- AKSD-WF-000055
- Vuln IDs
-
- V-237136
- V-76455
- Rule IDs
-
- SV-237136r831353_rule
- SV-91151
Checks: C-40355r640581_chk
Confirm Kona Site Defender is configured to connect to the correct origin server: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. In the "Origin Server" section, verify the "Origin Server Hostname" is valid. If the "Origin Server Hostname" is not valid, then this is a finding.
Fix: F-40318r640582_fix
Configure Kona Site Defender to connect to the correct origin server: 1. Log in to the Akamai Luna Portal (Caution-https://control.akamai.com). 2. Click the "Select Group or Property" button. 3. Select the configuration that is being reviewed. 4. Under the "Active Production" section, click on the active version. 5. Click the "Edit" button (if not already selected). 6. In the "Origin Server" section, change the "Origin Server Hostname" to the correct hostname. 7. Click the "Save" button. 8. Activate the configuration by clicking the "Activate" tab and the activate buttons for the proper network (either staging or production).