WG385 IIS7 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Web server documentation, sample code, example applications, and tutorials may be an exploitable threat to a web server. A production web server may only contain components that are operationally necessary (i.e., compiled code, scripts, web content, etc.). Delete all directories containing samples and any scripts used to execute the samples.

Solution

Remove sample code and documentation from the web server.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|I, CSCv6|9.1, Rule-ID|SV-32478r3_rule, STIG-ID|WG385_IIS7, Vuln-ID|V-13621

Plugin: Windows

Control ID: 1dcf4b8d74a1cbfb25e89007b5860ef2364ed049cf334e9ab9b13fc5a8d3b3f1