WG250 IIS6 - Users other than Auditors group must not have greater than read access to log files.

Information

A major tool in exploring the web site use, attempted use, unusual conditions, and problems are the access and error logs. In the event of a security incident, these logs can provide the SA and the Web Manager with valuable information. To ensure the integrity of the log files and protect the SA and Web Manager from a conflict of interest related to the maintenance of these files, only the members of the Auditors group will be granted permissions to move, copy, and delete these files in the course of their duties related to the archiving of these files.
NOTE: Update SITE_LOG_DIR to the appropriate value for the local environment

Solution

Ensure only the System, Administrators, and Auditors group has greater than read permission to the log files.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-9(4), 800-53|CM-6b., CAT|II, Rule-ID|SV-30017r1_rule, STIG-ID|WG250_IIS6, Vuln-ID|V-2252

Plugin: Windows

Control ID: 2ef18af9aa1f3ae2444ab67dc8d9c0f708a8d0804fa198b79c29b2b7916d753f