Skip Navigation

IISW-SV-000154: Web server must maintain the confidentiality of controlled information during transmission

The IIS 8.5 web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version.
To check compliance with IISW-SV-000154, complete the following steps:
  1. Review the web server documentation.
  2. Review the web server deployed configuration.
  3. Determine which version of TLS is being used.
If the TLS version is not an approved version according to NIST SP 800-52 or to the non-FIPS-approved enabled algorithms, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Configure the web server to use an approved TLS version according to NIST SP 800-52.
  2. Disable any non-approved TLS versions.