STIGQter STIGQter: STIG Summary: Microsoft IIS 10.0 Server Security Technical Implementation Guide Version: 3 Release: 7 Benchmark Date: 01 Apr 2026:

The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.

DISA Rule

SV-218788r1156543_rule

Vulnerability Number

V-218788

Group Title

SRG-APP-000099-WSR-000061

Rule Version

IIST-SV-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the IIS 10.0 web server IIS Manager.
Click the IIS 10.0 web server name.
Under "IIS", double-click the "Logging" icon.
Verify the "Format:" under "Log File" is configured to "W3C".
Select "Fields".
Under "Custom Fields", click "Add Field...".
For each field being added, give a name unique to what the field is capturing.
Click on the "Source Type" drop-down list and select "Request Header".
Click the "Source" drop-down list, and select "Connection".
Click "OK" to add.

Click the "Source Type" drop-down list, and select "Request Header".
Click the "Source" drop-down list, and select "Warning".
Click "OK" to add.
Click "Apply" under the "Actions" pane.

Check Contents

Note: If the server is hosting WSUS, this is Not Applicable.

Access the IIS 10.0 web server IIS Manager.
Click the IIS 10.0 web server name.
Under "IIS", double-click the "Logging" icon.
Verify the "Format:" under "Log File" is configured to "W3C".
Select "Fields".
Under "Custom Fields", verify the following fields have been configured:
Request Header >> Connection.
Request Header >> Warning.
If any of the above fields are not selected, this is a finding.

Vulnerability Number

V-218788

Documentable

False

Rule Version

IIST-SV-000110

Severity Override Guidance

Note: If the server is hosting WSUS, this is Not Applicable.

Access the IIS 10.0 web server IIS Manager.
Click the IIS 10.0 web server name.
Under "IIS", double-click the "Logging" icon.
Verify the "Format:" under "Log File" is configured to "W3C".
Select "Fields".
Under "Custom Fields", verify the following fields have been configured:
Request Header >> Connection.
Request Header >> Warning.
If any of the above fields are not selected, this is a finding.

Check Content Reference

M

Target Key

4052