# SP-008 Public Web Server Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for internet-facing web applications, covering network segmentation, input validation, session management, TLS configuration, DDoS protection, and secure deployment lifecycle for systems directly exposed to untrusted traffic.
Use when: Any organisation deploying web applications or APIs that are accessible from the public internet. This includes customer-facing portals, e-commerce platforms, SaaS applications, public APIs, content management systems, marketing websites handling form submissions, and any web-based service that processes user input.
Not when: Purely internal web applications that are not exposed to the internet and are protected by VPN or zero-trust network access may not require the full scope of this pattern, though many controls remain relevant.

## Controls (38, NIST SP 800-53 ids)
- Critical (6): AC-03, AC-07, CM-02, CM-07, RA-05, SC-05
- Important (17): AC-10, AC-12, AU-03, AU-07, CA-02, CM-03, CM-05, CP-02, CP-09, CP-10, IR-04, RA-03, SA-03, SA-08, SA-10, SC-08, SC-09
- Standard (15): AC-01, AC-09, AC-11, CA-04, CP-03, CP-06, CP-07, IA-01, IR-02, MA-02, MA-04, MA-06, PL-02, SC-11, SC-20
- Withdrawn from SP 800-53 by NIST: CA-04 (now in CA-02); SC-09 (now in SC-08)

## What each critical control mitigates (6)
- AC-03 Access Enforcement: T-WS-001, T-WS-009
- AC-07 Unsuccessful Logon Attempts: T-WS-004, T-WS-009
- CM-02 Baseline Configuration: T-WS-002, T-WS-006
- CM-07 Least Functionality: T-WS-002, T-WS-006
- RA-05 Vulnerability Monitoring and Scanning: T-WS-001, T-WS-002, T-WS-006, T-WS-007
- SC-05 Denial-of-service Protection: T-WS-003

## Threats and the controls that mitigate them (10)
- T-WS-001 SQL Injection and Command Injection: AC-03, SA-08, SA-10, RA-05
- T-WS-002 Cross-Site Scripting (XSS) and Content Injection: SA-08, CM-02, CM-07, RA-05
- T-WS-003 Distributed Denial of Service (DDoS): SC-05, CP-02, CP-07, CP-10
- T-WS-004 Credential Brute-Force and Stuffing Attacks: AC-07, AC-10, IA-01, AU-03
- T-WS-005 Session Hijacking and Fixation: AC-11, AC-12, SC-08, SC-09
- T-WS-006 Server Misconfiguration and Information Disclosure: CM-02, CM-07, CM-03, RA-05
- T-WS-007 Supply Chain Compromise (Third-Party Dependencies): SA-10, SA-03, CM-03, RA-05
- T-WS-008 Cryptographic Failures (Weak TLS, Expired Certificates): SC-08, SC-09, SC-11, SC-20
- T-WS-009 Unauthorised Access to Administrative Interfaces: AC-03, CM-05, AC-07, AU-03
- T-WS-010 Data Exfiltration Following Application Compromise: AU-07, IR-04, CP-09, SC-08

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-008/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-008/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 25 KB: /api/v1/patterns/SP-008
- Page for people: /patterns/sp-008/
- Related: SP-017 Secure Network Zone Module; SP-011 Cloud Computing Pattern; SP-014 Awareness and Training Pattern; SP-016 DMZ Module

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
