Item Search

NameAudit NamePluginCategory
1.1 IIST-SI-000201CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.2 IIST-SI-000202CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.5 IIST-SI-000206CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.18 IIST-SI-000227CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.20 IIST-SI-000228CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.22 IIST-SI-000230CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.29 IIST-SI-000238CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.41 IIST-SI-000262CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.1 Ensure 'global authorization rule' is set to restrict accessCIS IIS 8.0 v1.5.1 Level 1Windows

ACCESS CONTROL

2.2.22 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.30 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

7.15 Ensure TLS Cipher Suite ordering is configuredCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DISA_STIG_VMware_vSphere_7.0_RhttpProxy_v1r1.audit from DISA VMware vSphere 7.0 vCenter Appliance RhttpProxy v1r1 STIGDISA STIG VMware vSphere 7.0 RhttpProxy v1r1Unix
DISA_STIG_VMware_vSphere_7.0_SVC.audit from DISA VMware vSphere 7.0 vCenter Appliance Lookup Service v1r2 STIGDISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix
IIST-SI-000202 - The IIS 10.0 website session state cookie settings must be configured to Use Cookies mode.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IIST-SI-000202 - The IIS 10.0 website session state cookie settings must be configured to Use Cookies mode.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000225 - The IIS 10.0 website must be configured to limit the maxURL.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000225 - The IIS 10.0 website must be configured to limit the maxURL.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000226 - The IIS 10.0 website must be configured to limit the size of web requests.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000226 - The IIS 10.0 website must be configured to limit the size of web requests.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000227 - The IIS 10.0 websites Maximum Query String limit must be configured.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000227 - The IIS 10.0 websites Maximum Query String limit must be configured.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000228 - Non-ASCII characters in URLs must be prohibited by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000228 - Non-ASCII characters in URLs must be prohibited by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000229 - Double encoded URL requests must be prohibited by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 10.0 website.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server eventsDISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000136 - The IIS 10.0 web server must augment re-creation to a stable and known baseline.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000136 - The IIS 10.0 web server must augment re-creation to a stable and known baseline.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000147 - Access to web administration tools must be restricted to the web manager and the web managers designees.DISA IIS 10.0 Server v2r10Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000147 - Access to web administration tools must be restricted to the web manager and the web managers designees.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000152 - IIS 10.0 web server session IDs must be sent to the client using TLS.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000220 - The Request Smuggling filter must be enabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IISW-SI-000201 - The IIS 8.5 website session state must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000202 - The IIS 8.5 website session state cookie settings must be configured to Use Cookies mode.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000225 - The IIS 8.5 website must be configured to limit the maxURL.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000226 - The IIS 8.5 website must be configured to limit the size of web requests.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000227 - The IIS 8.5 websites Maximum Query String limit must be configured.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000229 - Double encoded URL requests must be prohibited by any IIS 8.5 website.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000230 - Unlisted file extensions in URL requests must be filtered by any IIS 8.5 website.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000262 - Interactive scripts on the IIS 8.5 web server must have restrictive access controls.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SV-000119 - The IIS 8.5 web server must not be both a website server and a proxy server.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

IISW-SV-000124 - The IIS 8.5 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled - MIME that invoke OS shell programs disabledDISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

IISW-SV-000136 - The IIS 8.5 web server must augment re-creation to a stable and known baseline.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SV-000152 - IIS 8.5 web server session IDs must be sent to the client using TLS.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION