Skip to content

Internet Information System (IIS) or its subcomponents must not be installed on a workstation.

An XCCDF Rule

Description

<VulnDiscussion>IIS is not installed by default. Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-253275r958478_rule
Severity
High
References
Updated



Remediation - Manual Procedure

Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.