Internet Information System (IIS) or its subcomponents must not be installed on a workstation.
An XCCDF Rule
Description
<VulnDiscussion>IIS is not installed by default. Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-253275r958478_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.