Quantcast
Channel: Ivanti User Community: Message List
Viewing all articles
Browse latest Browse all 12704

Re: Windows Server Hardening

$
0
0

Yes, that would cover one line item.

Here is what I have so far:

 

 

LANDesk ImplementationSimple DescriptionVuln IDSeverityGroup TitleRule IDSTIG IDRule Title
All IIS updates added to Scan group. Download rule created to add new patches to groupAll IIS PatchesV-2246highWG190SV-32635r1_ruleWG190 IIS7The web server must use a vendor-supported version of the web server software.
Not Out of the BoxV-2247highWG200SV-2247r2_ruleWG200 W13Only administrators are allowed access to the directory tree, the shell, or other operating system functions and utilities.
Not Out of the Box (Easy Script)V-6537highWG195SV-32381r1_ruleWG195 IIS7Anonymous access accounts must be restricted.
N/APhysical LocationV-13591highWA155SV-14165r1_ruleWA155Classified web servers will be afforded physical security commensurate with the classification of its content.
Not Out of the BoxV-13621highWG385SV-32478r1_ruleWG385 IIS7All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.
ST000009 : Check if IIS Lockdown tool has been runV-2251lowWG130SV-46363r1_ruleWG130 IIS7Programs and features not necessary for operations must be removed.
N/ADocumentationV-2257lowWA120SV-32638r1_ruleWA120 IIS7Administrative users and groups with access privilege to the web server must be documented.
Not Out of the BoxV-2265lowWG490SV-32640r1_ruleWG490 IIS7Java software installed on the production web server must be limited to .class files and the Java Virtual Machine.
Not Out of the BoxV-25994lowWA000-WI091SV-32645r1_ruleWA000-WI091Directory Browsing must be disabled on the production web server.
Not Out of the BoxV-26006lowWA000-WI6120SV-32657r1_ruleWA000-WI6120A global authorization rule to restrict access must exist on the web server.
Not Out of the BoxV-2234mediumWG040SV-32631r1_ruleWG040 IIS7Public web server resources must not be shared with private assets.
ST000019: Enable local Password ExpirationLocal Password Expiration <1yrV-2235mediumWG060SV-36487r2_ruleWG060 IIS7The service account ID used to run the web site must have its password changed at least annually.
V-2236mediumWG080SV-32632r2_ruleWG080 IIS7Installation of compilers on production web servers is prohibited.
V-2242mediumWA060SV-32633r1_ruleWA060 IIS7A public web server must be physically isolated in the enclave.
V-2243mediumWA070SV-32634r1_ruleWA070 IIS7A private web server must be located on a separate controlled access subnet.
V-2248mediumWG220SV-46357r1_ruleWG220 IIS7Access to web administration tools must be restricted to the web manager and the web managers designees.
V-2259mediumWG300SV-32332r1_ruleWG300 IIS7Web server system files must conform to minimum file permission requirements.
V-2261mediumWG330SV-32639r1_ruleWG330 IIS7A web server must limit e-mail to outbound only.
V-2271mediumWG440SV-32641r1_ruleWG440 IIS7Monitoring software must include CGI type files or equivalent programs.
V-6577mediumWG204SV-32643r1_ruleWG204 IIS7A web server must not be co-hosted with other services.
V-6754mediumWA000-WI080SV-32222r1_ruleWA000-WI080 IIS7The use of Internet Printing Protocol (IPP) must be disabled on the IIS web server.
V-13672mediumWG145SV-32479r2_ruleWG145 IIS7The private web server must use an approved DoD certificate validation process.
V-13700mediumWA000-WI100SV-46359r1_ruleWA000-WI100 IIS7The File System Object component must be disabled.
V-25999mediumWA000-WI6100SV-32650r1_ruleWA000-WI6100Unspecified file extensions must not be allowed to execute on the production web server.

Viewing all articles
Browse latest Browse all 12704

Trending Articles