STIGQter STIGQter: STIG Summary: Microsoft SharePoint 2013 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The SharePoint Central Administration site must not be accessible from Extranet or Internet connections.

DISA Rule

SV-223265r612235_rule

Vulnerability Number

V-223265

Group Title

SRG-APP-000212

Rule Version

SP13-00-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SharePoint Central Administration site to not be accessible from Extranet or Internet connections.

Block outside Central Administrator access.

Use an IIS IP address restrictions, firewall, or other filtering solutions to limit access to Central Administration site.

Check Contents

Review the SharePoint server configuration to ensure Central Administration site is not accessible from Extranet or Internet connections.

Check outside access to Central Administration.

On an administrative work station, open Central Administration and make note of the URL (i.e., http://sharepointserver:7040).

Try to open the Central Administration application on a regular user's workstation. Open a Web browser and type in the URL to Central Administration.

If the Central Administration can be opened, this is a finding.

Vulnerability Number

V-223265

Documentable

False

Rule Version

SP13-00-000150

Severity Override Guidance

Review the SharePoint server configuration to ensure Central Administration site is not accessible from Extranet or Internet connections.

Check outside access to Central Administration.

On an administrative work station, open Central Administration and make note of the URL (i.e., http://sharepointserver:7040).

Try to open the Central Administration application on a regular user's workstation. Open a Web browser and type in the URL to Central Administration.

If the Central Administration can be opened, this is a finding.

Check Content Reference

M

Target Key

4096

Comments