ref: DISA DB STIG SQL 2005 V8 ref: Vulnerability Key: V0015199 ref: STIG ID: DM6120-SQLServer9 ref: Severity: Category III Reporting Services Web service requests and HTTP access should be disabled if not required. Where not required, SOAP and URL access to the web service unnecessarily exposes the report server to attack via the SOAP and HTTP protocols. ref: U_INS_sqlserver9_v8r1.7_Checklist_20100827.pdf pg. 218