1.5.2 Enable Advanced IIS Logging

Information

Many of the fields available in Advanced Logging many can provide extensive, real-time data and details not otherwise obtainable. Developers and security professionals can use this information to identify and remediate application vulnerabilities/attack patterns.

Solution

IIS Advanced Logging can be configured for servers, Web sites, and directories in IIS Manager. To enable Advanced Logging using the UI: Open Internet Information Services (IIS) Manager Click the server in the Connections pane Double-click the Advanced Logging icon on the Home page Click Enable Advanced Logging in the Actions pane The fields that will be logged need to be configured using the Edit Logging Fields action. As with IIS's standard log files, their location should be changed. Note: There may be performance considerations depending on the extent of the configuration.

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CSCv6|3.1

Plugin: Windows

Control ID: 33d6afcac0b5e87d605932aadf813f0b8cb977b765fe42b0e82b4910d050e4b6