IIS 7.0 Server STIG

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: [email protected]


Version / Release: V1R18

Published: 2019-05-01

Updated At: 2019-05-03 21:24:07

Compare/View Releases

Select any two versions of this STIG to compare the individual requirements

Select any old version/release of this STIG to view the previous requirements




Severity Open Not Reviewed Not Applicable Not a Finding
Overall 0 0 0 0
Low 0 0 0 0
Medium 0 0 0 0
High 0 0 0 0
Drop CKL or SCAP (XCCDF) results here.

    Vuln Rule Version CCI Severity Title Description Status Finding Details Comments
    SV-32631r2_rule WG040 IIS7 MEDIUM Public web server resources must not be shared with private assets. It is important to segregate public web server resources from private resources located behind the DoD DMZ in order to protect private assets. When folders, drives or other resources are directly shared between the public web server and private servers th
    SV-36487r4_rule WG060 IIS7 MEDIUM The service account ID used to run the website must have its password changed at least annually. Normally, a service account is established for the web service to run under rather than permitting it to run as system or root. If the web service account requires a password, the password must be changed at least annually. It is a fundamental tenet of
    SV-32632r4_rule WG080 IIS7 MEDIUM Installation of compilers on production web servers is prohibited. The presence of a compiler on a production server facilitates the malicious user’s task of creating custom versions of programs and installing Trojan Horses or viruses.System Administrator
    SV-32633r3_rule WA060 IIS7 MEDIUM A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension. To minimize exposure of private assets to unnecessary risk by attackers, public web servers must be isolated from internal systems. Public web servers are by nature more vulnerable to attack from publically based sources, such as the public Internet. Onc
    SV-32634r2_rule WA070 IIS7 MEDIUM A private web server must be located on a separate controlled access subnet. Private web servers, which host sites that serve controlled access data, must be protected from outside threats in addition to insider threats, which can cause a disruption in service of the web server. To protect the private web server from these threats
    SV-32635r2_rule WG190 IIS7 HIGH The web server must use a vendor-supported version of the web server software. Several vulnerabilities are associated with older versions of web server software. As hot fixes and patches are issued, these solutions are included in the next version of the server software. Maintaining the web server at a current version makes the eff
    SV-2247r4_rule WG200 W13 HIGH Only administrators are allowed access to the directory tree, the shell, or other operating system functions and utilities. As a rule, accounts on a web server are to be kept to a minimum. Only administrators, web managers, developers, auditors, and web authors require accounts on the machine hosting the web server. This is in addition to the anonymous web user account. The re
    SV-46357r3_rule WG220 IIS7 MEDIUM Access to web administration tools must be restricted to the web manager and the web managers designees. The key web service administrative and configuration tools must only be accessible by the web server staff. All users granted this authority will be documented and approved by the ISSO. Access to the IIS Manager will be limited to authorized users and ad
    SV-46363r3_rule WG130 IIS7 LOW Programs and features not necessary for operations must be removed. Just as running unneeded services and protocols increase the attack surface of the web server, running unneeded utilities and programs is also an added risk to the web server.System AdministratorWeb Administrator
    SV-32638r2_rule WA120 IIS7 LOW Administrative users and groups with access privilege to the web server must be documented. There are typically several individuals and groups involved in running a production web-site. In most cases, several types of users on a web server can be identified, such as, SA's, Web Managers, Auditors, Authors, Developers, and the Clients. Nonetheles
    SV-32332r2_rule WG300 IIS7 MEDIUM Web server system files must conform to minimum file permission requirements. This check verifies the key web server system configuration files are owned by the SA or the web administrator controlled account. These same files that control the configuration of the web server, and thus its behavior, must also be accessible by the acc
    SV-32639r2_rule WG330 IIS7 MEDIUM A web server must limit e-mail to outbound only. Incoming e-mails have been known to provide hackers with access to servers. Disabling the incoming mail service prevents this type of attacks. Additionally, e-mail is a specialized application requiring the dedication of server resources. A production web
    SV-32640r2_rule WG490 IIS7 LOW Java software installed on the production web server must be limited to .class files and the Java Virtual Machine. Source code for a Java program is, many times, stored in files with either .java or .jpp file extensions. From the .java and .jpp files the Java compiler produces a binary file with an extension of .class. The .java or .jpp file could therefore reveal se
    SV-32641r3_rule WG440 IIS7 MEDIUM Monitoring software must include CGI type files or equivalent programs. By their very nature, CGI type files permit the anonymous web user to interact with data and perhaps store data on the web server. In many cases, CGI scripts exercise system-level control over the server’s resources. These files make appealing targets f
    SV-32381r2_rule WG195 IIS7 HIGH Anonymous access accounts must be restricted. Many of the security problems that occur are not the result of a user gaining access to files or data for which the user does not have permissions, but rather users are assigned incorrect permissions to unauthorized data. The files, directories, and data
    SV-32643r3_rule WG204 IIS7 MEDIUM A web server must not be co-hosted with other services. A detailed web server installation and configuration plan should be followed to provide standardization during the installation process. The installation and configuration plan should not support the co-hosting of multiple services, such as, Domain Name
    SV-32222r2_rule WA000-WI080 IIS7 MEDIUM The use of Internet Printing Protocol (IPP) must be disabled on the IIS web server. The use of Internet Printing Protocol (IPP) on an IIS web server allows client’s access to shared printers. This privileged access could allow remote code execution by increasing the web servers attack surface. Additionally, since IPP does not suppor
    SV-14165r3_rule WA155 HIGH Classified web servers will be afforded physical security commensurate with the classification of its content. When data of a classified nature is migrated to a web server, fundamental principles applicable to the safeguarding of classified material must be followed. A classified web server needs to be afforded physical security commensurate with the classificatio
    SV-32478r3_rule WG385 IIS7 HIGH All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. Web server documentation, sample code, example applications, and tutorials may be an exploitable threat to a web server. A production web server may only contain components that are operationally necessary (i.e., compiled code, scripts, web content, etc.)
    SV-32479r3_rule WG145 IIS7 MEDIUM The private web server must use an approved DoD certificate validation process. The Certificate Revocation List (CRL) is used for a number of reasons, for example, when an employee leaves, certificates expire, or if certificate keys become compromised and are reissued. Without the use of a certificate validation process, the server i
    SV-46359r4_rule WA000-WI100 IIS7 MEDIUM The File System Object component must be disabled. Some Component Object Model (COM) components are not required for most applications and should be removed if possible. Most notably, consider disabling the File System Object component; however, this will also remove the Dictionary object. Be aware some
    SV-32645r2_rule WA000-WI091 LOW Directory Browsing must be disabled on the production web server. Directory browsing allows the contents of a directory to be displayed upon request from a web client. If directory browsing is enabled for a directory in IIS, users could receive a web page listing the contents of the directory. If directory browsing is
    SV-32650r2_rule WA000-WI6100 MEDIUM Unspecified file extensions must not be allowed to execute on the production web server. By allowing unspecified file extensions to execute, the web servers attack surface is significantly increased. This increased risk can be reduced by only allowing specific ISAPI extensions or CGI extensions to run on the web server.Web Administrator
    SV-32657r2_rule WA000-WI6120 LOW A global authorization rule to restrict access must exist on the web server. Authorization rules can be configured at the server, web site, folder (including Virtual Directories), or file level. It is recommended that URL Authorization be configured to only grant access to the necessary security principals. Configuring a global A