Check: 5.016
Windows Vista STIG:
5.016
(in versions v6 r42 through v6 r41)
Title
Internet Information System (IIS) or its subcomponents are installed on a workstation. (Cat I impact)
Discussion
This is a Category 1 finding because not removing these services may allow unauthorized internet services to be hosted. Web sites should only be hosted on servers that have been designed for that purpose and can be adequately secured.
Check Content
Select “Start” Select “Control Panel” Select the “Add or Remove Programs” applet. Select “Add/Remove Windows Components”. If the entry for “Internet Information Services” is checked, then this is a finding. Documentable Explanation: If an application requires IIS or a subset to be installed to function, this needs be documented with the IAO. In addition, any applicable requirements from the Web Checklist must be addressed.
Fix Text
Configure the system to remove “Internet Information Services”.
Additional Identifiers
Rule ID: SV-29706r1_rule
Vulnerability ID: V-3347
Group Title: Internet Information System (IIS)
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |