DISA IIS 10.0 Server v3r6

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA IIS 10.0 Server v3r6

Updated: 7/28/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.2

Estimated Item Count: 43

File Details

Filename: DISA_STIG_IIS_10.0_Web_Server_v3r6.audit

Size: 135 kB

MD5: d0fc33f688c8accc89d9e19f4d8a6871
SHA256: dd3c02322098f6d5bf071968c03e1ef61d7cdd52104ba5d8a960bae93715faf8

Audit Changelog

 
Revision 1.2

Jul 28, 2026

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.1

Jun 12, 2026

Functional Update
  • IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
  • IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.
  • IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
  • IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
  • IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).
Informational Update
  • IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
  • IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
  • IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).