[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

IIS Admin Service (IISADMIN)

ID: oval:org.secpod.oval:def:80597Date: (C)2022-06-02   (M)2023-12-13
Class: COMPLIANCEFamily: windows




Enables the server to administer the IIS metabase. The IIS metabase stores configuration for the SMTP and FTP services. Note: This service is not installed by default. It is supplied with Windows, but is installed by enabling an optional Windows feature (Internet Information Services). Note #2: An organization may choose to selectively grant exceptions to web developers to allow IIS (or another web server) on their workstation, in order for them to locally test and develop web pages. However, the organization should track those machines and ensure the security controls and mitigations are kept up to date, to reduce risk of compromise. Hosting a website from a workstation is an increased security risk, as the attack surface of that workstation is then greatly increased. If proper security mitigations are not followed, the chance of successful attack increases significantly. Note: This security concern applies to any web server application installed on a workstation, not just IIS. Default: Not Installed (Automatic when installed) Counter Measure: The recommended state for this setting is Disabled or Not Installed. Potential Impact: IIS will not function, including Web, SMTP or FTP services. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\IIS Admin Service (2) REG: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IISADMIN!Start

Platform:
Microsoft Windows 10
Reference:
CCE-98505-1
CPE    1
cpe:/o:microsoft:windows_10
CCE    1
CCE-98505-1
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_10

© SecPod Technologies