STIGQter STIGQter: STIG Summary: Microsoft IIS 10.0 Server Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

All IIS 10.0 web server sample code, example applications, and tutorials must be removed from a production IIS 10.0 server.

DISA Rule

SV-218795r561041_rule

Vulnerability Number

V-218795

Group Title

SRG-APP-000141-WSR-000077

Rule Version

IIST-SV-000120

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remove any executable sample code, example applications, or tutorials which are not explicitly used by a production website.

Check Contents

Navigate to the following folders:

inetpub\
Program Files\Common Files\System\msadc
Program Files (x86)\Common Files\System\msadc

If the folder or sub-folders contain any executable sample code, example applications, or tutorials which are not explicitly used by a production website, this is a finding.

Vulnerability Number

V-218795

Documentable

False

Rule Version

IIST-SV-000120

Severity Override Guidance

Navigate to the following folders:

inetpub\
Program Files\Common Files\System\msadc
Program Files (x86)\Common Files\System\msadc

If the folder or sub-folders contain any executable sample code, example applications, or tutorials which are not explicitly used by a production website, this is a finding.

Check Content Reference

M

Target Key

4052

Comments