Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-16006 | 5.260 | SV-16958r1_rule | ECSC-1 | Medium |
Description |
---|
Windows Server 2008 includes additional features available for installation through Server Manager. The majority of these are unnecessary for the server roles and may also increase the attack surface of the system. |
STIG | Date |
---|---|
Windows 2008 Domain Controller Security Technical Implementation Guide | 2014-01-07 |
Check Text ( C-16647r1_chk ) |
---|
Start “Server Manager” under Adminstrative Tools Select “Features” node View Features Summary to determine any installed features. The “Add Features” link provides a complete list of available Features Any installed Features must be documented with the IAO to include the reason for installation and any mitigations of risk. Current Exceptions: Group Policy Management, Windows Server Backup Features, Bitlocker. If any unnecessary, undocumented Features are installed, then this is a finding. |
Fix Text (F-16029r1_fix) |
---|
Uninstall any unnecessary, undocumented Features. |