Skip Navigation

IIST-SI-000263: Remove backup interactive scripts

Backup interactive scripts on the IIS 10.0 server must be removed.
To check compliance with IIST-SI-000263 complete the following steps for each site hosted on the IIS 10.0 web server:
  1. Determine whether scripts are used on the web server for the subject website. Common file extensions include, but are not limited to: .cgi, .pl, .vb, .class, .c, .php, .asp, and .aspx. The scope of this requirement is to analyze only within the web server content directories, not the entire underlying operating system. If the website does not utilize CGI, this finding is not applicable.
  2. Open the IIS 10.0 Manager.
  3. Right-click the website name and click
    Explore
    .
  4. Search for the listed script extensions.
  5. Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or "copy of...".
If files with these extensions are found, your application is not compliant.
If your application is not compliant, remove the backup files from the production web server.