WG130 IIS6 - Programs and features not necessary for operations must be removed.

Information

Just as running unneeded services and protocols increase the attack surface of the web server, running unneeded utilities and programs is also an added risk to the web server.
Review the list of installed programs to ensure only those that are required for the system to run are listed.

Solution

Install only web support software on the web server. When other processes are supported by the web server, ensure a risk assessment has been performed and documented. If a database server is installed on the same platform as the web server, it must be on a separate drive or partition. Remove all unnecessary applications and programs.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CAT|III, Rule-ID|SV-38191r2_rule, STIG-ID|WG130_IIS6, Vuln-ID|V-2251

Plugin: Windows

Control ID: 8957649c249b658f86507b57b0fe69ee1bb8e05e86ccfb1ad9dee75f5dd88ace