Skip Navigation

IIST-SV-000154: Use approved TLS version

The IIS 10.0 web server must maintain the confidentiality of controlled information during transmission through the use of an approved Transport Layer Security (TLS) version.
To check compliance with IIST-SV-000154, review the web server documentation and deployed configuration to determine which version of TLS is being used.
If the TLS version is not TLS 1.2 or higher, according to NIST SP 800-52, or if non-FIPS-approved algorithms are enabled, your server is not compliant.
If your server is not compliant, configure the web server to use an approved TLS version according to NIST SP 800-52 and disable all non-approved versions.