Skip Navigation

IIST-SV-000131: Limit access to only administrative accounts

IIS 10.0 web server accounts that access the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.
To check compliance with IIST-SV-000131, complete the following steps:
  1. Obtain a list of the user accounts with access to the system, including all local and domain accounts.
  2. Review the privileges to the web server for each account.
  3. Verify with the System Administrator or the ISSO that all privileged accounts are mission essential and documented.
  4. Verify with the System Administrator or the ISSO that all non-administrator access to shell scripts and operating system functions are mission essential and documented.
If undocumented privileged accounts are found, your server is not compliant.
If undocumented non-administrator access to shell scripts and operating system functions are found, your server is not compliant.
If your IIS 10 installation supports Microsoft Exchange and is not otherwise hosting any content, this requirement is not applicable.
If your server is not compliant, complete the following steps:
  1. Ensure that non-administrators are not allowed access to the directory tree, the shell, or other operating system functions and utilities.
  2. Ensure that all non-administrator access to shell scripts and operating system functions is mission essential and documented.