Skip Navigation

IIST-SV-000117: Do not perform user management

The IIS 10.0 web server must not perform user management for hosted applications.
To check compliance with IIST-SV-000117, complete the following steps:
  1. Verify with the System Administrator (SA) if the IIS 10.0 web server is hosting an application.
  2. If the IIS 10.0 web server is hosting an application, verify with the SA that they can provide supporting documentation about how the application's user management is accomplished outside of the IIS 10.0 web server.
If the web server is hosting an application and the SA cannot provide the supporting documentation, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Reconfigure any hosted applications on the IIS 10.0 web server to perform user management outside the IIS 10.0 web server.
  2. Document how the hosted application user management is accomplished.