WG130 IIS7 - Programs and features not necessary for operations must be removed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Just as running unneeded services and protocols increase the attack surface of the web server, running unneeded utilities and programs is also an added risk to the web server.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remove all unapproved programs and roles from the production web server.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CSCv6|9.1, Rule-ID|SV-46363r3_rule, STIG-ID|WG130_IIS7, Vuln-ID|V-2251

Plugin: Windows

Control ID: db3aa2354a044ffde2916b19a61b3f80c0182bd28ad6d3a54e575aa37f525931