STIGQter STIGQter: STIG Summary: Microsoft IIS 10.0 Site Security Technical Implementation Guide Version: 2 Release: 16 Benchmark Date: 01 Jul 2026:

HTTPAPI Server version must be removed from the HTTP Response Header information.

DISA Rule

SV-278953r1192787_rule

Vulnerability Number

V-278953

Group Title

SRG-APP-000266-WSR-000159

Rule Version

IIST-SI-000270

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to "HKLM\System\CurrentControlSet\Services\HTTP\Parameters".

Create REG_DWORD "DisableServerHeader” and set it to "1".

Note: This can be performed multiple ways; this is an example.

Check Contents

Note: If the server is hosting WSUS, this is not applicable.

Open Registry Editor.

Navigate to "HKLM\System\CurrentControlSet\Services\HTTP\Parameters".

Verify "DisableServerHeader” is set to "1".

If REG_DWORD DisableServerHeader is not set to "1", this is a finding.

If the system administrator (SA) can show that Server Version information has been removed via other means, such as using a rewrite outbound rule, this is not a finding.

Vulnerability Number

V-278953

Documentable

False

Rule Version

IIST-SI-000270

Severity Override Guidance

Note: If the server is hosting WSUS, this is not applicable.

Open Registry Editor.

Navigate to "HKLM\System\CurrentControlSet\Services\HTTP\Parameters".

Verify "DisableServerHeader” is set to "1".

If REG_DWORD DisableServerHeader is not set to "1", this is a finding.

If the system administrator (SA) can show that Server Version information has been removed via other means, such as using a rewrite outbound rule, this is not a finding.

Check Content Reference

M

Target Key

4051