SV-218820r561041_rule
V-218820
SRG-APP-000439-WSR-000152
IIST-SV-000152
CAT II
10
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select "system.webServer/asp".
Expand the "session" section.
Select "True" for the "keepSessionIdSecure" setting.
Select "Apply" from the "Actions" pane.
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under the "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select "system.webServer/asp".
Expand the "session" section.
Verify the "keepSessionIdSecure" is set to "True".
If the "keepSessionIdSecure" is not set to "True", this is a finding.
V-218820
False
IIST-SV-000152
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under the "Management" section, double-click the "Configuration Editor" icon.
From the "Section:" drop-down list, select "system.webServer/asp".
Expand the "session" section.
Verify the "keepSessionIdSecure" is set to "True".
If the "keepSessionIdSecure" is not set to "True", this is a finding.
M
4052