WG060 IIS7 - The service account ID used to run the website must have its password changed at least annually.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Normally, a service account is established for the web service to run under rather than permitting it to run as system or root. If the web service account requires a password, the password must be changed at least annually. It is a fundamental tenet of security that passwords are not to be null and must not be set to never expire.

Solution

Configure the service account ID used to run the web-site to have its password changed at least annually, or use the local system account.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CAT|II, Rule-ID|SV-36487r4_rule, STIG-ID|WG060_IIS7, Vuln-ID|V-2235

Plugin: Windows

Control ID: 76e8c8c5224bf3ad0ae4cedfa18633c8b4595433a4437e8b8c4ff680cdae15ef