Skip Navigation

IIST-SV-000147: Restrict access to web administration tools

Access to web administration tools must be restricted to the web manager and the web manager's designees.
To check compliance with IIST-SV-000147, complete the following steps:
  1. Right-click
    InetMgr.exe
    , and then click
    Context
    >
    Properties
    .
  2. Click the
    Security
    tab.
  3. Review the groups and user names.
  4. Compare the local documentation authorizing specific users against the users observed when reviewing the groups and users.
The following accounts may have full control privileges:
  • TrustedInstaller
  • Web Managers
  • Web Manager designees
  • CREATOR OWNER: Full Control, Subfolders and files only
The following accounts may have read and execute or read permissions:
  • Non Web Manager Administrators
  • ALL APPLICATION PACKAGES (built-in security group)
  • ALL RESTRICTED APPLICATION PACKAGES (built-in security group)
  • SYSTEM
  • Users
Specific users may have read and execute and read permissions.
If any other access is observed, your server is not compliant.
If your server is not compliant, restrict access to the web administration tool to only the web manager and the web manager's designees.