Skip Navigation

IIST-SV-000141: Follow access policy

Remote access to the IIS 10.0 web server must follow access policy or work with enterprise tools designed to enforce policy requirements.
If web administration is performed at the console, this check is not applicable.
If web administration is performed remotely, to check compliance with IIST-SV-000141, verify that the following conditions are met:
  • If administration of the server is performed remotely, it is only performed securely by System Administrators.
  • If website administration or web application administration has been delegated, those users are documented and approved by the ISSO.
  • Remote administration is in compliance with any requirements contained within the Windows Server STIGs and any applicable Network STIGs.
  • Remote administration of any kind is restricted to documented and authorized personnel.
  • All users performing remote administration are authenticated.
  • All remote sessions are encrypted and use FIPS 140-2-approved protocols. FIPS 140-2-approved TLS versions include TLS V1.2 or greater.
Review with site management how remote administration is configured on the website, if applicable. If remote management meets the criteria listed above, your server is compliant. If remote management is used and does not meet the criteria listed above, your server is not compliant.
If your server is not compliant, ensure that the web server administration is only performed over a secure path.