Revision 1.5

Mar 10, 2022
Functional Update
  • IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.
  • IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events - Connection
  • IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events - Warning
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - Custom Authorization
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - Custom Content-Type
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - Referer
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - User Agent
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - User Name
  • IIST-SI-000235 - The Idle Time-out monitor for each IIS 10.0 website must be enabled.
  • IIST-SI-000257 - The application pools pinging monitor for each IIS 10.0 website must be enabled.
Informational Update
  • IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.
Miscellaneous
  • Metadata updated.
Removed
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - Custom HTTP_USER_AGENT
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event - Custom User-Agent
  • IIST-SI-000253 - The amount of virtual memory an application pool uses for each IIS 10.0 website must be explicitly set.
  • IIST-SI-000254 - The amount of private memory an application pool uses for each IIS 10.0 website must be explicitly set.