Skip to content

Microsoft IIS 10.0 Server Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • ASP.NET version must be removed from the HTTP Response Header information.

    <VulnDiscussion>HTTP Response Headers contain information that could enable an attacker to gain access to an information system. Failure to p...
    Rule Low Severity
  • SRG-APP-000141-WSR-000015

    <GroupDescription></GroupDescription>
    Group
  • The Request Smuggling filter must be enabled.

    &lt;VulnDiscussion&gt;Security scans show Request Smuggling vulnerability on IIS server. The vulnerability allows a remote attacker to perform HTT...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules