UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Internet Information System (IIS) or its subcomponents are installed on a workstation.


Overview

Finding ID Version Rule ID IA Controls Severity
V-3347 5.016 SV-3347r1_rule ECSC-1 High
Description
This is a Category 1 finding because not removing these services may allow unauthorized internet services to be hosted. Web sites should only be hosted on servers that have been designed for that purpose and can be adequately secured.
STIG Date
Windows XP Security Technical Implementation Guide 2014-04-02

Details

Check Text ( C-544r1_chk )
Select “Start”
Select “Control Panel”
Select the “Add or Remove Programs” applet.
Select “Add/Remove Windows Components”.

If the entry for “Internet Information Services” is checked, then this is a finding.

Documentable Explanation: If an application requires IIS or a subset to be installed to function, this needs be documented with the IAO. In addition, any applicable requirements from the Web Checklist must be addressed.
Fix Text (F-5826r1_fix)
Configure the system to remove “Internet Information Services”.