Item Search

NameAudit NamePluginCategory
1.1 Ensure web content is on non-system partitionCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.1 Ensure Web Content Is on Non-System PartitionCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

1.1 IIST-SI-000201CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.2 IIST-SI-000202CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.5 IIST-SI-000206CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.8 IIST-SI-000210CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.9 IIST-SI-000214CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.11 IIST-SI-000216CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.13 IIST-SI-000220CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.17 IIST-SI-000226CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.18 IIST-SI-000227CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.22 IIST-SI-000230CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.27 IIST-SI-000236CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

DISA_STIG_IIS_10.0_Web_Site_v2r14.audit from DISA Microsoft IIS 10.0 Site v2r14 STIGDISA IIS 10.0 Site v2r14Windows
IIST-SI-000202 - The IIS 10.0 website session state cookie settings must be configured to Use Cookies mode.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IIST-SI-000202 - The IIS 10.0 website session state cookie settings must be configured to Use Cookies mode.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000216 - The IIS 10.0 website must have resource mappings set to disable the serving of certain file types.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000216 - The IIS 10.0 website must have resource mappings set to disable the serving of certain file types.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000220 - A private IIS 10.0 website authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA IIS 10.0 Site v2r14Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000220 - A private IIS 10.0 website authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000227 - The IIS 10.0 websites Maximum Query String limit must be configured.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000227 - The IIS 10.0 websites Maximum Query String limit must be configured.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000228 - Non-ASCII characters in URLs must be prohibited by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000229 - Double encoded URL requests must be prohibited by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000236 - The IIS 10.0 websites connectionTimeout setting must be explicitly configured to disconnect an idle session.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000236 - The IIS 10.0 websites connectionTimeout setting must be explicitly configured to disconnect an idle session.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IISW-SI-000201 - The IIS 8.5 website session state must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000202 - The IIS 8.5 website session state cookie settings must be configured to Use Cookies mode.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000205 - The enhanced logging for each IIS 8.5 website must be enabled and capture, record, and log all content related to a user sessionDISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000210 - The IIS 8.5 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000214 - The IIS 8.5 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled - MIME that invoke OS shell programs disabledDISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000216 - The IIS 8.5 website must have resource mappings set to disable the serving of certain file types.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000217 - The IIS 8.5 website must have Web Distributed Authoring and Versioning (WebDAV) disabled.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000227 - The IIS 8.5 websites Maximum Query String limit must be configured.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

SHPT-00-000531 - SharePoint sites must not use NTLM - SharePoint sites must not use NTLM.DISA STIG SharePoint 2010 v1r9Windows

IDENTIFICATION AND AUTHENTICATION

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - ConnectionTimeoutDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - maxBandwidthDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - maxConnectionsDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Script Source permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Write permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WG310 IIS6 - A web site must not contain a robots.txt file.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT