DISA IIS 10.0 Site v2r14

Audit Details

Name: DISA IIS 10.0 Site v2r14

Updated: 6/12/2026

Authority: DISA STIG

Plugin: Windows

Revision: 1.1

Estimated Item Count: 44

File Details

Filename: DISA_STIG_IIS_10.0_Web_Site_v2r14.audit

Size: 128 kB

MD5: c62e69b0c329642fdb6f5dd1ca84ce4e
SHA256: deeb49c57988b94634b30c8349d462f78dca12887ab7c5ca0a558ad85997697e

Audit Changelog

 
Revision 1.1

Jun 12, 2026

Functional Update
  • IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.
  • IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events.
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
  • IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.
  • IIST-SI-000252 - The maximum number of requests an application pool can process for each IIS 10.0 website must be explicitly set.
  • IIST-SI-000255 - The application pool for each IIS 10.0 website must have a recycle time explicitly set.
Informational Update
  • IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.
  • IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events.
  • IIST-SI-000210 - The IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
  • IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.
  • IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.
  • IIST-SI-000252 - The maximum number of requests an application pool can process for each IIS 10.0 website must be explicitly set.
  • IIST-SI-000255 - The application pool for each IIS 10.0 website must have a recycle time explicitly set.