Skip Navigation

IIST-SV-000144: Conform to minimum file permission requirements

IIS 10.0 web server system files must conform to minimum file permission requirements.
To check compliance with IIST-SV-000144, complete the following steps:
  1. Open Explorer and navigate to the
    inetpub
    directory.
  2. Right-click
    inetpub
    and select
    Properties
    .
  3. Click the
    Logging
    icon.
  4. Click the
    Security
    tab.
  5. Verify the permissions for the following users:
    • System: Full control
    • Administrators: Full control
    • TrustedInstaller: Full control
    • ALL APPLICATION PACKAGES (built-in security group): Read and execute
    • ALL RESTRICTED APPLICATION PACKAGES (built-in security group): Read and execute
    • Users: Read and execute, list folder contents
    • CREATOR OWNER: Full Control, Subfolders and files only
If the permissions for the users listed above are less restrictive, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Open Explorer and navigate to the
    inetpub
    directory.
  2. Right-click
    inetpub
    and select
    Properties
    .
  3. Click the
    Security
    tab.
  4. Set the following permissions:
    • System: Full control
    • Administrators: Full control
    • TrustedInstaller: Full control
    • ALL APPLICATION PACKAGES (built-in security group): Read and execute
    • ALL RESTRICTED APPLICATION PACKAGES (built-in security group): Read and execute
    • Users: Read and execute, list folder contents
    • CREATOR OWNER: Special permissions to subkeys