SP13-00-000150 - The SharePoint Central Administration site must not be accessible from Extranet or Internet connections.

Information

SharePoint must prevent the presentation of information system management-related functionality at an interface utilized by general, (i.e., non-privileged), users.

The Central Administrator is an application used to manage SharePoint system settings and the settings of the web applications running under SharePoint. The Central Administrator application should both be protected using a defense-in-depth approach. Regular users should not be able to access the Central Administrator as the first line of defense. The second line of defense is regular users do not have user ids defined in the Central Administration application.

Solution

Configure the SharePoint Central Administration site to not be accessible from Extranet or Internet connections.

Block outside Central Administrator access.

Use an IIS IP address restrictions, firewall, or other filtering solutions to limit access to Central Administration site.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_SharePoint_2013_V2R3_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-2(1), CAT|II, CCI|CCI-001083, Rule-ID|SV-223265r612235_rule, STIG-ID|SP13-00-000150, STIG-Legacy|SV-74423, STIG-Legacy|V-59993, Vuln-ID|V-223265

Plugin: Windows

Control ID: bc6aab0ef98f0ab69df62069e09bb6ba3ccbae6d6fe9ef3135d6231b75a7d8d5