WA155 IIS6 - Classified web servers must be afforded physical security commensurate with the classification of its content.

Information

When data of a classified nature is migrated to a web server, fundamental principles applicable to the safeguarding of classified material must be followed. A classified web server needs to be afforded physical security commensurate with the classification of its content to ensure the protection of the data it houses.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Relocate the web server to a location appropriate to classified devices.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip