Internet Information System (IIS) or its subcomponents must not be installed on a workstation.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-253275 | WN11-00-000100 | SV-253275r958478_rule | CCI-000381 | high |
| Description | ||||
| IIS is not installed by default. Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be adequately secured. | ||||
| STIG | Date | |||
| Microsoft Windows 11 Security Technical Implementation Guide | 2025-05-15 | |||
Related Frameworks
3 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
CM-7
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.4.6
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000381
1.00
- DISA · 2 · disa_xccdf · related
Details
Check Text (C-253275r958478_chk)
Verify it has not been installed on the system.
Run "Programs and Features".
Select "Turn Windows features on or off".
If the entries for "Internet Information Services" or "Internet Information Services Hostable Web Core" are selected, this is a finding.
If an application requires IIS or a subset to be installed to function, this needs be documented with the ISSO. In addition, any applicable requirements from the IIS STIG must be addressed.
Fix Text (F-56678r828908_fix)
Uninstall "Internet Information Services" or "Internet Information Services Hostable Web Core" from the system.