Skip to content

Microsoft IIS 10.0 Site Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000141-WSR-000082

    <GroupDescription></GroupDescription>
    Group
  • Mappings to unused and vulnerable scripts on the IIS 10.0 website must be removed.

    &lt;VulnDiscussion&gt;IIS 10.0 will either allow or deny script execution based on file extension. The ability to control script execution is contr...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000083

    <GroupDescription></GroupDescription>
    Group
  • The IIS 10.0 website must have resource mappings set to disable the serving of certain file types.

    &lt;VulnDiscussion&gt;IIS 10.0 will either allow or deny script execution based on file extension. The ability to control script execution is contr...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000085

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules