SV-218823r561041_rule
V-218823
SRG-APP-000516-WSR-000079
IIST-SV-000156
CAT I
10
Access the IIS 10.0 web server.
Access the "Apps" menu. Under Administrative Tools, select Computer Management.
In left pane, expand "Local Users and Groups" and click on "Users".
Change passwords for any local accounts present that are used by IIS 10.0, then verify with System Administrator default passwords have been changed.
Develop an internal process for changing passwords on a regular basis.
Access the IIS 10.0 web server.
Access the "Apps" menu. Under "Administrative Tools", select "Computer Management".
In left pane, expand "Local Users and Groups" and click "Users".
Review the local users listed in the middle pane.
If any local accounts are present and used by IIS 10.0, verify with System Administrator that default passwords have been changed.
If passwords have not been changed from the default, this is a finding.
V-218823
False
IIST-SV-000156
Access the IIS 10.0 web server.
Access the "Apps" menu. Under "Administrative Tools", select "Computer Management".
In left pane, expand "Local Users and Groups" and click "Users".
Review the local users listed in the middle pane.
If any local accounts are present and used by IIS 10.0, verify with System Administrator that default passwords have been changed.
If passwords have not been changed from the default, this is a finding.
M
4052