1. Home
  2. Security Hardening
  3. DISA IIS 8.5 Site V2R1
  4. IISW-SI-000221 – Anonymous IIS 8.5 website access accounts must be restricted – Anonymous username

IISW-SI-000221 – Anonymous IIS 8.5 website access accounts must be restricted – Anonymous username

Details

Many of the security problems that occur are not the result of a user gaining access to files or data for which the user does not have permissions, but rather users are assigned incorrect permissions to unauthorized data. The files, directories, and data that are stored on the web server need to be evaluated and a determination made concerning authorized access to information and programs on the server. Only authorized users and administrative accounts will be allowed on the host server in order to maintain the web server, applications, and review the server operations.

Solution

Remove the Anonymous access account from all privileged accounts and all privileged groups.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles