UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Internet Information System (IIS) or its subcomponents must not be installed on a workstation.


Overview

Finding ID Version Rule ID IA Controls Severity
V-3347 5.016 SV-25253r2_rule ECSC-1 High
Description
Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.
STIG Date
Windows 7 Security Technical Implementation Guide 2015-09-02

Details

Check Text ( C-62073r1_chk )
To verify whether IIS is installed, perform the following:

Open Control Panel.
Select "Programs and Features".
Select "Turn Windows features on or off".

If the entry for "Internet Information Services" is selected, this is a finding.

If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed.
Fix Text (F-66971r1_fix)
Remove "Internet Information Services" from the system.