Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Secure Web Servers: Protecting Web Sites That Are Accessed by the Public

Published

Author(s)

Shirley M. Radack

Abstract

This bulletin summarizes the contents of NIST Special Publication 800-44, Version 2, Guidelines on Securing Public Web Servers. The publication details the steps that organizations should take to plan, install, and maintain secure Web server software and their underlying operating systems. The bulletin covers the security risks to public Web servers and NIST recommendations to organizations about: how to secure, install, and configure the operating system that supports the Web server; how to secure, install, and configure Web server software; how to deploy appropriate network protection mechanisms, such as firewalls, routers, switches, and intrusion detection and intrusion prevention systems; the steps for maintaining the secure configuration of the operating system and server software through the application of appropriate patches and upgrades; the requirements for security testing; the methods for monitoring logs, and for managing backups of data and operating system files; and how to use, publicize and protect information and data on Web servers in a careful and systematic manner.
Citation
ITL Bulletin -

Keywords

Internet, network security, operating systems, public Web servers, security management, system security, vulnerabilities, Web browsers, Web servers

Citation

Radack, S. (2008), Secure Web Servers: Protecting Web Sites That Are Accessed by the Public, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=51335 (Accessed May 29, 2024)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created January 31, 2008, Updated January 27, 2020