DISA IIS 8.5 Site v2r7

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA IIS 8.5 Site v2r7

Updated: 9/19/2023

Authority: DISA STIG

Plugin: Windows

Revision: 1.3

Estimated Item Count: 71

Audit Changelog

 
Revision 1.3

Sep 19, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.2

Jul 24, 2023

Functional Update
  • IISW-SI-000219 - Each IIS 8.5 website must be assigned a default host header.
  • IISW-SI-000220 - A private websites authentication mechanism must use client certificates to transmit session identifier to assure integrity.
  • IISW-SI-000242 - The IIS 8.5 private website must employ cryptographic mechanisms (TLS) and require client certificates.
  • IISW-SI-000252 - The maximum number of requests an application pool can process for each IIS 8.5 website must be explicitly set.
  • IISW-SI-000255 - The application pool for each IIS 8.5 website must have a recycle time explicitly set - Regular Time Interval
  • IISW-SI-000255 - The application pool for each IIS 8.5 website must have a recycle time explicitly set - Schedule
Revision 1.1

Apr 12, 2023

Miscellaneous
  • Metadata updated.
  • References updated.