Check: SHPT-00-000690
Sharepoint 2010 SRG:
SHPT-00-000690
(in versions v1 r8 through v1 r7)
Title
The Central Administration site must not be accessible from Extranet or Internet connections. (Cat II impact)
Discussion
SharePoint must prevent the presentation of information system management-related functionality at an interface utilized by general, (i.e., non-privileged), users. Central Administration is an application used to manage SharePoint system settings and the settings of the web applications running under SharePoint. The Central Administration application should be protected using a defense-in-depth approach. Regular users should not be able to access the Central Administration as the first line of defense. The second line of defense is that regular users do not have user ids defined in the Central Administration application.
Check Content
Check outside access to Central Administration. 1. On an administrative work station, open Central Administration and make note of the URL (i.e., http://sharepointserver:7040). 2. Try to open the Central Administration application on a regular user’s workstation. Open a Web browser and type in the URL to Central Administration. If Central Administration can be opened, it is a finding.
Fix Text
Block outside Central Administration access. Use IIS IP address restrictions, firewall, or other filtering solutions to limit access to the Central Administration site.
Additional Identifiers
Rule ID:
Vulnerability ID: V-28281
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001083 |
The information system prevents the presentation of information system management-related functionality at an interface for non-privileged users. |
Controls
Number | Title |
---|---|
SC-2 (1) |
Interfaces For Non-Privileged Users |