4.12 ProcessModel

Information

The principle of a non-privileged user is one that is running under least privilege, meaning they are non-admin users with limited functionality. NOTE: This check audits the default system drive. If your organization's configuration is different the '%systemdrive%' variable will need to be adjusted. NOTE2: Change <framework_version> to the version of .NET that is in use by your organization.

Solution

Make sure 'ProcessModel password' is set use Aspnet_setreg.exe utility to store encrypted credentials in the registry.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(7)

Plugin: Windows

Control ID: 1f4172d73b6929a9a90e5498f44f8e703cacdbcde9d071bb0424a968ea95e8d2