5.3 Ensure 'ETW Logging' is enabled

Information

IIS introduces a new logging method. Administrators can now send logging information to Event Tracing for Windows (ETW).

IIS flushes log information to disk, therefore prior to IIS, administrators do not have access to real-time logging information. Text-based log files can also be difficult and time consuming to process. By enabling ETW, administrators have access to use standard query tools for viewing real-time logging information.

NOTE: IIS was not discovered as installed on the target.

See Also

https://workbench.cisecurity.org/benchmarks/14293

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Windows

Control ID: f56334ffd19cc15192a8c83839452b8c52b11616014cddbc9bbb3f0ccbef00b9