Check: WN11-00-000100
Microsoft Windows 11 STIG:
WN11-00-000100
(in versions v1 r6 through v1 r1)
Title
Internet Information System (IIS) or its subcomponents must not be installed on a workstation. (Cat I impact)
Discussion
IIS is not installed by default. Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.
Check Content
Verify it has not been installed on the system. Run "Programs and Features". Select "Turn Windows features on or off". If the entries for "Internet Information Services" or "Internet Information Services Hostable Web Core" are selected, this is a finding. If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed.
Fix Text
Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.
Additional Identifiers
Rule ID: SV-253275r828909_rule
Vulnerability ID: V-253275
Group Title: SRG-OS-000095-GPOS-00049
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |