Skip to content
Back to skills

Cis Apache 9.1

ASecurity

Ensure the TimeOut Is Set Properly

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 30, 2026
securitygosecurity

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-apache-9.1 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Apache 9.1?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Apache 9.1
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-apache-9-1/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-apache-9-1)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-apache-9.1
description: "Ensure the TimeOut Is Set Properly"
category: cis-apache
version: "3.6.0"
author: cyberstrike-official
tags: [cis, apache, linux, dos, denial-of-service, timeout]
cis_id: "9.1"
cis_benchmark: "CIS Apache HTTP Server 2.2 Benchmark v3.6.0"
tech_stack: [linux, apache]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# Ensure the TimeOut Is Set Properly

## Description

The `TimeOut` directive controls the maximum time in seconds that Apache HTTP server will wait for an Input/Output call to complete. It is recommended that the `TimeOut` directive be set to `10` or less.

## Rationale

One common technique for DoS is to initiate many connections to the server. By decreasing the timeout for old connections, the server can free resources more quickly and be more responsive. By making the server more efficient, it will be more resilient to DoS conditions.

**Important Notice**: There is a slow form of DoS attack not adequately mitigated by these controls, such as the Slow Loris DoS attack of June 2009 http://ha.ckers.org/slowloris/. Upgrading to Apache 2.4 is recommended.

## Impact

None documented

## Audit Procedure

Perform the following steps to determine if the recommended state is implemented:

Verify that the `Timeout` directive is specified in the Apache configuration files to have a value of `10` seconds or less.

## Remediation

Perform the following to implement the recommended state:

Add or modify the `Timeout` directive in the Apache configuration files to have a value of `10` seconds or less.

```
Timeout 10
```

## Default Value

```
Timeout 300
```

## References

1. https://httpd.apache.org/docs/2.2/mod/core.html#timeout

## CIS Controls

**Version 6**

9 Limitation and Control of Network Ports, Protocols, and Services
Limitation and Control of Network Ports, Protocols, and Services

**Version 7**

5.1 Establish Secure Configurations
Maintain documented, standard security configuration standards for all authorized
operating systems and software.

## Profile

Level 1 | Scored

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…