Check: IISW-SV-000103
Microsoft IIS 8.5 Server STIG:
IISW-SV-000103
(in versions v2 r7 through v1 r0.1)
Title
Both the log file and Event Tracing for Windows (ETW) for the IIS 8.5 web server must be enabled. (Cat II impact)
Discussion
Internet Information Services (IIS) on Windows Server 2012 provides basic logging capabilities. However, because IIS takes some time to flush logs to disk, administrators do not have access to logging information in real-time. In addition, text-based log files can be difficult and time-consuming to process. In IIS 8.5, the administrator has the option of sending logging information to Event Tracing for Windows (ETW). This option gives the administrator the ability to use standard query tools, or create custom tools, for viewing real-time logging information in ETW. This provides a significant advantage over parsing text-based log files that are not updated in real time. Satisfies: SRG-APP-000092-WSR-000055, SRG-APP-000108-WSR-000166, SRG-APP-000358-WSR-000063
Check Content
Open the IIS 8.5 Manager. Click the IIS 8.5 server name. Click the "Logging" icon. Under Log Event Destination, verify the "Both log file and ETW event" radio button is selected. If the "Both log file and ETW event" radio button is not selected, this is a finding.
Fix Text
Open the IIS 8.5 Manager. Click the IIS 8.5 server name. Click the "Logging" icon. Under Log Event Destination, select the "Both log file and ETW event" radio button. Under the "Actions" pane, click "Apply".
Additional Identifiers
Rule ID: SV-214401r879562_rule
Vulnerability ID: V-214401
Group Title: SRG-APP-000092-WSR-000055
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000139 |
Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure. |
CCI-001464 |
Initiates session audits automatically at system start-up. |
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |