Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-2235 | WG060 | SV-2235r1_rule | Medium |
Description |
---|
Normally, a service account is established for the web service to run under rather than permitting it to run as system or root. The passwords on such accounts must be changed at least annually. It is a fundamental tenet of security that passwords are not to be null and must not to be set to never expire. |
STIG | Date |
---|---|
IIS 7.0 Server STIG | 2019-03-22 |
Check Text ( C-29901r1_chk ) |
---|
Review the site password policy. |
Fix Text (F-27578r3_fix) |
---|
Configure the service account ID used to run the web-site to have its password changed at least annually, or use the local system account. |