WG130 - All utility programs, not necessary for operations, are not removed or disabled.

Information

Vulnerability Key: V0002251
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 12.4 CM Process
Severity: Category III
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.3, Web Site Administration Policies & Procedures, With
Amendments and Corrections incorporated in red italics
Just as running unneeded services and protocols is a danger to the web server at the lower levels
of the OSI model, running unneeded utilities and programs is a danger at the application layer of
the OSI model. Office suites, development tools and graphical editors are examples of such
programs that are troublesome in two ways. These individual productivity tools have no legitimate
place or use on an enterprise, production web server. Such tools are also prone to their own
security risks and their existence on a web server adds to the inherent risk of running a web server.
Such tools require patch maintenance via a separate track from the web server software and
maintaining their patches and hotfixes can expose the web server to additional risks by altering
configurations and introducing additional unwanted features and services.
Review the list of installed programs to ensure only those that are required for the system to run are listed.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 887c5c47b7223ba1f42db46207515e85a6b0cc0d6259bfa494d556a16569fbb1