STIGQter STIGQter: STIG Summary: Microsoft IIS 10.0 Site Security Technical Implementation Guide Version: 2 Release: 16 Benchmark Date: 01 Jul 2026:

The log information from the IIS 10.0 website must be protected from unauthorized modification or deletion.

DISA Rule

SV-283673r1193224_rule

Vulnerability Number

V-283673

Group Title

SRG-APP-000120-WSR-000070

Rule Version

IIST-SI-000275

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the IIS 10.0 Manager.

Click the IIS 10.0 web server name.

For each Site:

Click the "Logging" icon.

Click "Browse" and navigate to the directory where the log files are stored.

Right-click the log file directory to review and click "Properties".

Click the "Security" tab.

Set the log file permissions for the appropriate group(s).

Click "OK".

Select "Apply" in the "Actions" pane.

Check Contents

This does not apply to service account IDs used by automated services necessary to process, manage, and store log files.

Open the IIS 10.0 Manager.

Click the IIS 10.0 web server name.

For each Site:

Click the "Logging" icon.

Click "Browse" and navigate to the directory where the log files are stored.

Right-click the log file directory to review.

Click "Properties".

Click the "Security" tab.

Verify log file access is restricted as follows. Otherwise, this is a finding.

SYSTEM - Full Control, This folder, subfolders and files
Administrators - Full Control, This folder, subfolders and files (Lower permission levels are permitted)

Note: A "Web Administrators", etc., type group that is an approved group of administrators is also allowed and must be given "Full Control, This folder, subfolders and files" permissions. (Lower permission levels are permitted.)

Vulnerability Number

V-283673

Documentable

False

Rule Version

IIST-SI-000275

Severity Override Guidance

This does not apply to service account IDs used by automated services necessary to process, manage, and store log files.

Open the IIS 10.0 Manager.

Click the IIS 10.0 web server name.

For each Site:

Click the "Logging" icon.

Click "Browse" and navigate to the directory where the log files are stored.

Right-click the log file directory to review.

Click "Properties".

Click the "Security" tab.

Verify log file access is restricted as follows. Otherwise, this is a finding.

SYSTEM - Full Control, This folder, subfolders and files
Administrators - Full Control, This folder, subfolders and files (Lower permission levels are permitted)

Note: A "Web Administrators", etc., type group that is an approved group of administrators is also allowed and must be given "Full Control, This folder, subfolders and files" permissions. (Lower permission levels are permitted.)

Check Content Reference

M

Target Key

4051