Revision 1.1

Aug 11, 2022
Functional Update
  • IIST-SV-000118 - The IIS 10.0 web server must only contain functions necessary for operation.
  • IIST-SV-000123 - The IIS 10.0 web server must be reviewed on a regular basis to remove any Operating System features, utility programs, plug-ins, and modules not necessary for operation.
  • IIST-SV-000148 - The IIS 10.0 web server must not be running on a system providing any other role.
  • IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
Removed
  • IIST-SV-000121 - The accounts created by uninstalled features (i.e., tools, utilities, specific, etc.) must be deleted from the IIS 10.0 server.