Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-44 Version 2

Guidelines on Securing Public Web Servers

Date Published: September 2007

Supersedes: SP 800-44 (10/09/2002)


Miles Tracy (Federal Reserve Information Technology), Wayne Jansen (NIST), Karen Scarfone (NIST), Theodore Winograd (BAH)



Web server; Web server security
Control Families

Audit and Accountability; Configuration Management; Contingency Planning; Identification and Authentication; Planning; System and Communications Protection


Download URL

Supplemental Material:
None available

Document History:
10/09/07: SP 800-44 Version 2 (Final)