Yes, that would cover one line item.
Here is what I have so far:
LANDesk Implementation | Simple Description | Vuln ID | Severity | Group Title | Rule ID | STIG ID | Rule Title |
All IIS updates added to Scan group. Download rule created to add new patches to group | All IIS Patches | V-2246 | high | WG190 | SV-32635r1_rule | WG190 IIS7 | The web server must use a vendor-supported version of the web server software. |
Not Out of the Box | V-2247 | high | WG200 | SV-2247r2_rule | WG200 W13 | Only administrators are allowed access to the directory tree, the shell, or other operating system functions and utilities. | |
Not Out of the Box (Easy Script) | V-6537 | high | WG195 | SV-32381r1_rule | WG195 IIS7 | Anonymous access accounts must be restricted. | |
N/A | Physical Location | V-13591 | high | WA155 | SV-14165r1_rule | WA155 | Classified web servers will be afforded physical security commensurate with the classification of its content. |
Not Out of the Box | V-13621 | high | WG385 | SV-32478r1_rule | WG385 IIS7 | All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. | |
ST000009 : Check if IIS Lockdown tool has been run | V-2251 | low | WG130 | SV-46363r1_rule | WG130 IIS7 | Programs and features not necessary for operations must be removed. | |
N/A | Documentation | V-2257 | low | WA120 | SV-32638r1_rule | WA120 IIS7 | Administrative users and groups with access privilege to the web server must be documented. |
Not Out of the Box | V-2265 | low | WG490 | SV-32640r1_rule | WG490 IIS7 | Java software installed on the production web server must be limited to .class files and the Java Virtual Machine. | |
Not Out of the Box | V-25994 | low | WA000-WI091 | SV-32645r1_rule | WA000-WI091 | Directory Browsing must be disabled on the production web server. | |
Not Out of the Box | V-26006 | low | WA000-WI6120 | SV-32657r1_rule | WA000-WI6120 | A global authorization rule to restrict access must exist on the web server. | |
Not Out of the Box | V-2234 | medium | WG040 | SV-32631r1_rule | WG040 IIS7 | Public web server resources must not be shared with private assets. | |
ST000019: Enable local Password Expiration | Local Password Expiration <1yr | V-2235 | medium | WG060 | SV-36487r2_rule | WG060 IIS7 | The service account ID used to run the web site must have its password changed at least annually. |
V-2236 | medium | WG080 | SV-32632r2_rule | WG080 IIS7 | Installation of compilers on production web servers is prohibited. | ||
V-2242 | medium | WA060 | SV-32633r1_rule | WA060 IIS7 | A public web server must be physically isolated in the enclave. | ||
V-2243 | medium | WA070 | SV-32634r1_rule | WA070 IIS7 | A private web server must be located on a separate controlled access subnet. | ||
V-2248 | medium | WG220 | SV-46357r1_rule | WG220 IIS7 | Access to web administration tools must be restricted to the web manager and the web managers designees. | ||
V-2259 | medium | WG300 | SV-32332r1_rule | WG300 IIS7 | Web server system files must conform to minimum file permission requirements. | ||
V-2261 | medium | WG330 | SV-32639r1_rule | WG330 IIS7 | A web server must limit e-mail to outbound only. | ||
V-2271 | medium | WG440 | SV-32641r1_rule | WG440 IIS7 | Monitoring software must include CGI type files or equivalent programs. | ||
V-6577 | medium | WG204 | SV-32643r1_rule | WG204 IIS7 | A web server must not be co-hosted with other services. | ||
V-6754 | medium | WA000-WI080 | SV-32222r1_rule | WA000-WI080 IIS7 | The use of Internet Printing Protocol (IPP) must be disabled on the IIS web server. | ||
V-13672 | medium | WG145 | SV-32479r2_rule | WG145 IIS7 | The private web server must use an approved DoD certificate validation process. | ||
V-13700 | medium | WA000-WI100 | SV-46359r1_rule | WA000-WI100 IIS7 | The File System Object component must be disabled. | ||
V-25999 | medium | WA000-WI6100 | SV-32650r1_rule | WA000-WI6100 | Unspecified file extensions must not be allowed to execute on the production web server. |