6.1 Ensure FTP requests are encrypted - Control Channel

Information

The new FTP Publishing Service for IIS supports adding an SSL certificate to an FTP site. Using an SSL certificate with an FTP site is also known as FTP-S or FTP over Secure Socket Layers (SSL). FTP-S is an RFC standard (RFC 4217) where an SSL certificate is added to an FTP site and thereby making it possible to perform secure file transfers.

By using SSL, the FTP transmission is encrypted and secured from point to point and all FTP traffic as well as credentials are thereby guarded against interception.

NOTE: This check requires FTP services insalled, and FTP services have not been found as being installed on the target.

See Also

https://workbench.cisecurity.org/files/165