Check: 5.016
Windows 7 STIG:
5.016
(in versions v1 r32 through v1 r25)
Title
Internet Information System (IIS) or its subcomponents must not be installed on a workstation. (Cat I impact)
Discussion
Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.
Check Content
To verify whether IIS is installed, perform the following: Open Control Panel. Select "Programs and Features". Select "Turn Windows features on or off". If the entry for "Internet Information Services" is selected, this is a finding. If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed.
Fix Text
Remove "Internet Information Services" from the system.
Additional Identifiers
Rule ID: SV-25253r2_rule
Vulnerability ID: V-3347
Group Title: Internet Information System (IIS)
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |