UCF STIG Viewer Logo

The service account ID used to run the web site will have its password changed at least annually.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2235 WG060 SV-2235r1_rule Medium
Description
Normally, a service account is established for the web service to run under rather than permitting it to run as system or root. The passwords on such accounts must be changed at least annually. It is a fundamental tenet of security that passwords are not to be null and must not to be set to never expire.
STIG Date
IIS 7.0 Server STIG 2019-03-22

Details

Check Text ( C-29901r1_chk )
Review the site password policy.
Fix Text (F-27578r3_fix)
Configure the service account ID used to run the web-site to have its password changed at least annually, or use the local system account.