Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3347 | 5.016 | SV-25253r1_rule | ECSC-1 | High |
Description |
---|
This is a Category 1 finding because not removing these services may allow unauthorized internet services to be hosted. Web sites should only be hosted on servers that have been designed for that purpose and can be adequately secured. |
STIG | Date |
---|---|
Windows 7 Security Technical Implementation Guide | 2013-03-14 |
Check Text ( C-26828r1_chk ) |
---|
To verify if IIS is installed, perform the following: Open Control Panel. Select “Programs and Features”. Select “Turn Windows features on or off”. If the entry for “Internet Information Services” is selected, then this is a finding. Documentable Explanation: If an application requires IIS or a subset to be installed to function, this needs be documented with the IAO. In addition, any applicable requirements from the Web Checklist must be addressed. |
Fix Text (F-5826r1_fix) |
---|
Configure the system to remove “Internet Information Services”. |