1. Home
  2. Security Hardening
  3. DISA STIG IIS 6.0 Server V6R16
  4. WG130 IIS6 – Programs and features not necessary for operations must be removed.

WG130 IIS6 – Programs and features not necessary for operations must be removed.

Details

Just as running unneeded services and protocols increase the attack surface of the web server, running unneeded utilities and programs is also an added risk to the web server.

Review the list of installed programs to ensure only those that are required for the system to run are listed.

Solution

Install only web support software on the web server. When other processes are supported by the web server, ensure a risk assessment has been performed and documented. If a database server is installed on the same platform as the web server, it must be on a separate drive or partition. Remove all unnecessary applications and programs.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles