Jun 12, 2026 Functional Update- IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
- IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.
- IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
- IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
- IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
- IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
- IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).
Informational Update- IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.
- IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
- IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
- IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.
- IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).
|