UCF STIG Viewer Logo

Internet Information System (IIS) or its subcomponents must not be installed on a workstation.


Overview

Finding ID Version Rule ID IA Controls Severity
WN08-GE-000016 WN08-GE-000016 WN08-GE-000016_rule High
Description
Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Web sites must only be hosted on servers that have been designed for that purpose and can be adequately secured.
STIG Date
Windows 8 Security Technical Implementation Guide 2012-11-21

Details

Check Text ( C-WN08-GE-000016_chk )
Verify if IIS is not installed by performing the following:

Search for "Features".
Select "Turn Windows features on or off".

If the entries for "Internet Information Services" or "Internet Information Services Hostable Web Core" are selected, this is a finding.

If an application requires IIS or a subset to be installed to function, this needs be documented with the IAO. In addition, any applicable requirements from the Web Checklist must be addressed.
Fix Text (F-WN08-GE-000016_fix)
Remove "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.