IIS 10.0 Server STIG Checklist
23 items · Security · Medium difficulty · 4 hours
Step-by-step checklist to apply the IIS 10.0 Server STIG and harden your web server.
-
Gather STIG packages and resources
Download official DISA STIGs, XCCDF files, SCC automated content and checksums.
-
Download Microsoft IIS 10.0 Server STIG
Obtain latest Server STIG package from DISA and verify checksum.
-
Download Microsoft IIS 10.0 Site STIG
Obtain Site STIG package (site-level requirements) and verify checksum.
-
Download XCCDF and SCC automated content
Get automated benchmarking content for scanning and remediation tools.
-
Review STIG requirements and scope
Read STIG guidance to understand which controls apply to your environment.
-
Backup IIS configuration and website content
Export applicationHost.config, site content, and SSL certificates before changes.
-
Apply operating system updates and security patches
Patch Windows Server and dependent components before STIG changes.
-
Ensure .NET Framework 4.5+ is installed and updated
Confirm required .NET version for session state and related settings.
-
Apply IIS Server STIG settings
Implement server-level STIG controls (global IIS configuration).
-
Disable directory browsing and default documents
Prevent unintended content disclosure by disabling directory listing.
-
Remove or secure sample websites and demo files
Delete or restrict access to default/sample content included with IIS.
-
Enforce authentication and authorization for admin areas
Require strong authentication and restrict access to management paths.
-
Harden TLS and cipher suites
Configure secure protocols, ciphers, and TLS settings at OS/IIS level.
-
Disable SSLv2 and SSLv3
Turn off legacy protocols to prevent protocol-level attacks.
-
Disable weak ciphers (RC4, 3DES) and enable TLS1.2/1.3
Prioritize modern, secure ciphers and protocol versions.
-
Enable strong TLS settings and forward secrecy
Set secure cipher order and prefer forward-secret suites.
-
Enable logging and monitor audit settings
Configure IIS, Windows Event, and request logging for audits.
-
Restrict management access and use least-privilege accounts
Limit admin accounts and use role-based access control.
-
Configure firewall and network controls for IIS server
Restrict unnecessary inbound ports and separate DMZ/internal rules.
-
Run automated compliance scan (SCC/XCCDF) and review findings
Execute automated benchmarks to compare configuration against STIG rules.
-
Remediate findings and re-run scans
Fix identified issues, document changes, and verify with another scan.
-
Document changes, maintenance windows, and rollback plans
Record implemented controls, planned windows, and rollback steps.
-
Schedule regular review and update of STIGs and resources
Plan periodic reviews to apply updated STIG versions and checksums.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.