3.9 Ensure that SharePoint application servers are protected by a reverse proxy

Information

A reverse proxy is server component that sits between the internet and the web servers. It
accepts HTTPS requests, provides various services, and forwards the requests to one or
many servers.

Rationale:

Having a point at which one can inspect, transform and route HTTPS requests before they
reach the SharePoint web servers provides significant benefits. A reverse proxy can hide
the topology and characteristics of the back-end SharePoint servers by removing the need
for direct internet access. A reverse proxy can be placed in an internet facing DMZ, and hide
the SharePoint web servers inside a non-public subnet.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Implement a reverse proxy to process all HTTPS requests and route them to the SharePoint
servers.

Impact:

A malicious attacker can directly attack a SharePoint server that is placed in the DMZ.

See Also

https://workbench.cisecurity.org/files/2395

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|12

Plugin: Windows

Control ID: 2a1e9fdbbb3cea716a7f0322078e47e998d3b17c34d2c4fd32a1425b08721047