WG220 IIS7 - Access to web administration tools must be restricted to the web manager and the web managers designees.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The key web service administrative and configuration tools must only be accessible by the web server staff. All users granted this authority will be documented and approved by the ISSO. Access to the IIS Manager will be limited to authorized users and administrators.

Solution

Restrict access to the web administration tool to only the web manager and the web manager's designees.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-46357r3_rule, STIG-ID|WG220_IIS7, Vuln-ID|V-2248

Plugin: Windows

Control ID: c9030b67741b6964b27007c58393f5031b9ca16b886cb5c16423b09cb0384953