Item Search

NameAudit NamePluginCategory
1.3 IIST-SI-000203CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.4 IIST-SI-000204CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

1.15 IIST-SI-000223CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.19 IIST-SI-000224CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.20 IIST-SI-000228CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.21 IIST-SI-000229CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.23 IIST-SI-000231CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.25 IIST-SI-000234CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.30 IIST-SI-000239CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

7.4 Ensure TLS 1.0 is enabledCIS IIS 7 L1 v1.8.0Windows
CIS Security Benchmark For Microsoft IIS 7.0/7.5 v1.8.0 Level I.CIS IIS 7 L1 v1.8.0Windows
CIS Security Benchmark For Microsoft IIS 7.0/7.5 v1.8.0 Level II.CIS IIS 7 L2 v1.8.0Windows
DISA_IIS_6.0_Web_Site_v6r16.audit from DISA Microsoft IIS 6.0 Site v6r16 STIGDISA STIG IIS 6.0 Site Checklist v6r16Windows
DISA_IIS_8.5_Web_Server_v2r7.audit from DISA Microsoft IIS 8.5 Server v2r7 STIGDISA IIS 8.5 Server v2r7Windows
DISA_IIS_8.5_Web_Site_v2r9.audit from DISA Microsoft IIS 8.5 Site v2r9 STIGDISA IIS 8.5 Site v2r9Windows
DISA_STIG_Microsoft_IIS_10.0_Site_v2r16.audit from DISA Microsoft IIS 10.0 Site STIG v2r16DISA Microsoft IIS 10.0 Site STIG v2r16Windows
IIST-SI-000203 - A private IIS 10.0 website must only accept Secure Socket Layer (SSL) connections.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000203 - A private IIS 10.0 website must only accept Secure Socket Layer (SSL) connections.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IIST-SI-000204 - A public IIS 10.0 website must only accept Secure Socket Layer (SSL) connections when authentication is required.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IIST-SI-000204 - A public IIS 10.0 website must only accept Secure Socket Layer (SSL) connections when authentication is required.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000223 - The IIS 10.0 website must generate unique session identifiers that cannot be reliably reproduced.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000223 - The IIS 10.0 website must generate unique session identifiers that cannot be reliably reproduced.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000224 - The IIS 10.0 website document directory must be in a separate partition from the IIS 10.0 websites system files.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000224 - The IIS 10.0 website document directory must be in a separate partition from the IIS 10.0 websites system files.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000226 - The IIS 10.0 website must be configured to limit the size of web requests.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000226 - The IIS 10.0 website must be configured to limit the size of web requests.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000228 - Non-ASCII characters in URLs must be prohibited by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000229 - Double encoded URL requests must be prohibited by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000231 - Directory Browsing on the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000231 - Directory Browsing on the IIS 10.0 website must be disabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IISW-SI-000203 - A private IIS 8.5 website must only accept Secure Socket Layer connections.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000204 - A public IIS 8.5 website must only accept Secure Socket Layer connections when authentication is required.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000223 - The IIS 8.5 website must generate unique session identifiers that cannot be reliably reproduced.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000224 - The IIS 8.5 website document directory must be in a separate partition from the IIS 8.5 websites system files.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000226 - The IIS 8.5 website must be configured to limit the size of web requests.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000228 - Non-ASCII characters in URLs must be prohibited by any IIS 8.5 website.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000229 - Double encoded URL requests must be prohibited by any IIS 8.5 website.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 8.5 website.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000231 - Directory Browsing on the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000234 - Debugging and trace information used to diagnose the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000239 - The IIS 8.5 websites must utilize ports, protocols, and services according to PPSM guidelines.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000246 - Cookies exchanged between the IIS 8.5 website and the client must use SSL/TLS, have cookie properties set to prohibit client-side scripts from reading the cookie data and must not be compressed.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION