Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

ITL Bulletin

Keeping Information Technology (IT) System Servers Secure: A General Guide to Good Practices

Date Published: October 2008


Shirley Radack (NIST)



information systems security; information technology; network servers; public Web servers; server security; risk management; security controls; security management; Web applications.
Control Families

Access Control; Audit and Accountability; Configuration Management; Identification and Authentication; Incident Response; Maintenance; Physical and Environmental Protection; Planning; System and Communications Protection; System and Information Integrity


Download (pdf)

Supplemental Material:
None available

Document History:
10/15/08: ITL Bulletin (Final)


Security and Privacy

general security & privacy, maintenance, planning

Laws and Regulations

OMB Circular A-130