WG040 IIS7 - Public web server resources must not be shared with private assets.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

It is important to segregate public web server resources from private resources located behind the DoD DMZ in order to protect private assets. When folders, drives or other resources are directly shared between the public web server and private servers the intent of data and resource segregation can be compromised.

Resources, such as, printers, files, and folders/directories must not be shared between public web servers and assets located within the internal network.

Solution

Configure the public web server to not have a trusted relationship with any system resource that is also not accessible to the public. Web content is not to be shared via Microsoft shares or NFS mounts.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-32631r2_rule, STIG-ID|WG040_IIS7, Vuln-ID|V-2234

Plugin: Windows

Control ID: 8097a09317a3296a91c91ab3852e5c2ca9be3a8461b1f4d065a5c6d215849365