DISA IIS 10.0 Server v2r5

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA IIS 10.0 Server v2r5

Updated: 2/21/2023

Authority: Operating Systems and Applications

Plugin: Windows

Revision: 1.4

Estimated Item Count: 82

Audit Changelog

 
Revision 1.4

Feb 21, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.3

Feb 3, 2023

Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.2

Dec 7, 2022

Miscellaneous
  • Variables updated.
Revision 1.1

Aug 11, 2022

Functional Update
  • IIST-SV-000118 - The IIS 10.0 web server must only contain functions necessary for operation.
  • IIST-SV-000123 - The IIS 10.0 web server must be reviewed on a regular basis to remove any Operating System features, utility programs, plug-ins, and modules not necessary for operation.
  • IIST-SV-000148 - The IIS 10.0 web server must not be running on a system providing any other role.
  • IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
Removed
  • IIST-SV-000121 - The accounts created by uninstalled features (i.e., tools, utilities, specific, etc.) must be deleted from the IIS 10.0 server.
Revision 1.0

May 17, 2022

Miscellaneous
  • Metadata updated.