Skip to main content

Networking / Loadbalancer / Controls / DEV

Scrub Sensitive Headers

CCC.LB.CN07 · Networking

Remove headers that disclose internal details or software versions from HTTP responses.

Related Capabilities

IDTitleDescription
CCC.Core.CP14API AccessThe service exposes a port enabling external actors to interact programmatically with the service and its resources using HTTP protocol methods such as GET, POST, PUT, and DELETE.

Related Threats

IDTitleDescription
CCC.Core.TH15Automated Enumeration and Reconnaissance by Non-human EntitiesAutomated processes may be used to gather details about service and child resource elements such as APIs, file systems, or directories. This information can reveal vulnerabilities, misconfigurations, and the network topology, which can be used to plan an attack against the system, the service, or its child resources.

Assessment Requirements

IDTextApplicability
CCC.LB.CN07.AR01When responses pass through the load balancer, the "Server" header MUST be replaced with "lb".tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-2Data in transit is protected
NIST_800_53SC-13Cryptographic protection