Internet Information System (IIS) or its subcomponents must not be installed on a workstation.

From Windows 8/8.1 Security Technical Implementation Guide

Part of Internet Information System (IIS)

Associated with: CCI-000381

SV-48074r2_rule Internet Information System (IIS) or its subcomponents must not be installed on a workstation.

Vulnerability discussion

Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured.

Check content

Verify IIS is not installed by performing the following: Search for "Features". Select "Turn Windows features on or off". If the entries for "Internet Information Services" or "Internet Information Services Hostable Web Core" are selected, this is a finding. If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed.

Fix text

Remove "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer