SharePoint must implement an information system isolation boundary that minimizes the number of nonsecurity functions included within the boundary containing security functions.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-223260 | SP13-00-000125 | SV-223260r1043178_rule | CCI-001184 | high |
| Description | ||||
| The information system isolates security functions from nonsecurity functions by means of an isolation boundary (implemented via partitions and domains) controlling access to and protecting the integrity of, the hardware, software, and firmware that perform those security functions. The information system maintains a separate execution domain (e.g., address space) for each executing process. | ||||
| STIG | Date | |||
| Microsoft SharePoint 2013 Security Technical Implementation Guide | 2024-12-10 | |||
Related Frameworks
3 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
SC-23
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.13.15
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-001184
1.00
- DISA · 2 · disa_xccdf · related
Details
Check Text (C-223260r1043178_chk)
Review the SharePoint server configuration to ensure an information system isolation boundary that minimizes the number of nonsecurity functions included within the boundary containing security functions are implemented.
Log on to the server that hosts the farm's Central Administration website.
Open IIS Manager.
Expand "Sites" tree view and right-click the web application named "SharePoint Central Administration".
Select "Edit Bindings ...".
Confirm the site is bound to an out-of-band (OOB) IP address.
If the site is bound to a production IP address or not bound to a specific IP address, this is a finding.
Fix Text (F-24921r430838_fix)
Configure the SharePoint server to implement an information system isolation boundary that minimizes the number of nonsecurity functions included within the boundary containing security functions.
Log on to the server that hosts the farm's Central Administration website.
Open IIS Manager.
Expand "Sites" tree view and right-click the web application named "SharePoint Central Administration".
Select "Edit Bindings ...".
Select the site binding record and click "Edit".
From the "IP Address" dropdown list, select an OOB IP address.
Click "Ok".
*NOTE: If the Central Administration site has multiple site bindings, steps will need to be repeated for each site binding.