CIS IIS 7 L2 v1.8.0

Audit Details

Name: CIS IIS 7 L2 v1.8.0

Updated: 12/22/2023

Authority: CIS

Plugin: Windows

Revision: 1.16

Estimated Item Count: 34

File Details

Filename: CIS_v1.8_MS_IIS_7_Level_2.audit

Size: 79 kB

MD5: 8e05986fce69c4b833ec3f3173d15810
SHA256: cd5ceb2505f05f4c38ffc95464d66cf162099ba82eb2f550ca219161855cdfc5

Audit Changelog

 
Revision 1.16

Dec 22, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.15

Apr 12, 2023

Miscellaneous
  • Metadata updated.
  • Platform check updated.
Revision 1.14

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.13

Jan 4, 2023

Miscellaneous
  • Metadata updated.
Revision 1.12

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.11

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.10

Jun 17, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.9

Feb 1, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.8

Sep 29, 2020

Miscellaneous
  • References updated.
Revision 1.7

Jun 28, 2020

Functional Update
  • 2.4 Ensure 'forms authentication' is set to use cookies - Applications
  • 2.4 Ensure 'forms authentication' is set to use cookies - Default
  • 2.4 Ensure 'forms authentication' is set to use cookies - Not Enabled
  • 3.2 Ensure 'debug' is turned off
  • 3.2 Ensure 'debug' is turned off - Applications
  • 3.2 Ensure 'debug' is turned off - Default
  • 3.3 Ensure Custom Error Messages are not Off
  • 3.3 Ensure Custom Error Messages are not Off - Applications
  • 3.3 Ensure Custom Error Messages are not Off - Default
  • 3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely
  • 3.5 Ensure ASP.NET stack tracing is not enabled
  • 3.5 Ensure ASP.NET stack tracing is not enabled - Applications
  • 3.5 Ensure ASP.NET stack tracing is not enabled - Default
  • 3.6 Ensure 'httpcookie' mode is configured for session state
  • 3.6 Ensure 'httpcookie' mode is configured for session state - Applications
  • 3.6 Ensure 'httpcookie' mode is configured for session state - Default
  • 3.7 Ensure 'cookies' are set with HttpOnly attribute
  • 3.7 Ensure 'cookies' are set with HttpOnly attribute - Applications
  • 3.7 Ensure 'cookies' are set with HttpOnly attribute - Default
Informational Update
  • 2.4 Ensure 'forms authentication' is set to use cookies - Not Enabled
  • 3.2 Ensure 'debug' is turned off
  • 3.3 Ensure Custom Error Messages are not Off
  • 3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely
  • 3.5 Ensure ASP.NET stack tracing is not enabled
  • 3.6 Ensure 'httpcookie' mode is configured for session state
  • 3.7 Ensure 'cookies' are set with HttpOnly attribute