GSA / https

The HTTPS-Only Standard for federal domains (M-15-13), and implementation guidance.
https://https.cio.gov
Other
248 stars 87 forks source link

Added two FAQ entries to the guide to clarify the applicability of M-15-13 #229

Closed egyptiankarim closed 7 years ago

egyptiankarim commented 7 years ago

Attempting to address two common arguments for what falls into scope for M-15-13 compliance auditing that stems from what it means to be a "web server". The content of a server's response is frequently being used to debate whether a listening network service qualifies as in-scope; chief among these arguments are those that conflate the availability of a web page with the availability of an HTTP service, and those that misconstrue the meaning of 4xx and 5xx status codes.

konklone commented 7 years ago

Fixed by #130.