WG242 IIS7 - Log files must consist of the required data fields.

Information

Log files are a critical component to the successful management of an IS used within the DoD. By generating log files with useful information web administrators can leverage them in the event of a disaster, malicious attack, or other site specific needs.

Solution

1. Open the IIS Manager.
2. Click the site name.
3. Click the Logging icon.
4. Under Format select W3C.
5. Select the following fields: Date, Time, Client IP Address, User Name, Method, URI Query, Protocol Status, and Referrer.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-12, CAT|II, CSCv6|6.2, Rule-ID|SV-32480r3_rule, STIG-ID|WG242_IIS7, Vuln-ID|V-13688

Plugin: Windows

Control ID: 5325a08f9c6190647e4b90577ee2e6e4a35bc689ec53ffafcc00d655528d8e8d