Skip to content

Microsoft IIS 10.0 Site Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.

    Controlling what a user of a hosted application can access is part of the security posture of the web server. Any time a user can access more functionality than is needed for the operation of the h...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000082

    Group
  • SRG-APP-000141-WSR-000083

    Group
  • The IIS 10.0 website must have resource mappings set to disable the serving of certain file types.

    IIS 10.0 will either allow or deny script execution based on file extension. The ability to control script execution is controlled through two features with IIS 10.0, Request Filtering and Handler ...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000085

    Group
  • The IIS 10.0 website must have Web Distributed Authoring and Versioning (WebDAV) disabled.

    A web server can be installed with functionality that by its nature is not secure. Web Distributed Authoring (WebDAV) is an extension to the HTTP protocol that, when developed, was meant to allow u...
    Rule Medium Severity
  • SRG-APP-000142-WSR-000089

    Group
  • SRG-APP-000172-WSR-000104

    Group
  • A private IIS 10.0 website authentication mechanism must use client certificates to transmit session identifier to assure integrity.

    A DoD private website must use PKI as an authentication mechanism for web users. Information systems residing behind web servers requiring authorization based on individual identity must use the id...
    Rule Medium Severity
  • SRG-APP-000211-WSR-000031

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules