DISA IIS 10.0 Server v3r6

Audit Details

Name: DISA IIS 10.0 Server v3r6

Updated: 6/12/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.1

Estimated Item Count: 43

File Details

Filename: DISA_STIG_IIS_10.0_Web_Server_v3r6.audit

Size: 152 kB

MD5: 80cc4aa3202314fa1c4f7ffeaa7c55aa
SHA256: 8727b0d8270eae143f8d0a511acaf945c9517d4e4cd75838f98bcb1d3ff8f856

Audit Changelog

 
Revision 1.1

Jun 12, 2026

Functional Update
  • IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
  • IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.
  • IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
  • IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
  • IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).
Informational Update
  • IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
  • IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
  • IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
  • IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).