UCF STIG Viewer Logo

The IIS 8.5 website must have a unique application pool.


Overview

Finding ID Version Rule ID IA Controls Severity
V-76865 IISW-SI-000251 SV-91561r1_rule Medium
Description
Application pools isolate sites and applications to address reliability, availability, and security issues. Sites and applications may be grouped according to configurations, although each site will be associated with a unique application pool.
STIG Date
IIS 8.5 Site Security Technical Implementation Guide 2018-01-03

Details

Check Text ( C-76521r1_chk )
Open the IIS 8.5 Manager.

Click "Application Pools".

In the list of Application Pools, review the "Applications" column and verify none show more than "1" application.

If any Application Pools show being applied to more than 1 application, this is a finding.
Fix Text (F-83561r1_fix)
Open the IIS 8.5 Manager.

Click the site name under review.

Assign a unique application pool to each website.