V-218742
CAT IIThe IIS 10.0 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.
- Ships Affected
- 2
- Total Findings
- 4
- Open
- 3
- Closed
- 1
Check Text
Note: If this server is hosting WSUS, this requirement is Not Applicable.
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Access the IIS 10.0 web server IIS 10.0 Manager.
Under "IIS", double-click the "Logging" icon.
Verify the "Format:" under "Log File" is configured to "W3C".
Select "Fields".
Under "Standard Fields", verify "User Agent", "User Name", and "Referrer" are selected.
Under "Custom Fields", verify the following fields have been configured:
Request Header >> Authorization
Response Header >> Content-Type
If any of the above fields are not selected, this is a finding.
Fix Text
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Access the IIS 10.0 web server IIS 10.0 Manager.
Select the website being reviewed.
Under "IIS", double-click the "Logging" icon.
Configure the "Format:" under "Log File" to "W3C".
Select "Fields".
Under "Standard Fields", select "User Agent", "User Name", and "Referrer".
Under "Custom Fields", select the following fields:
Request Header >> Authorization
Response Header >> Content-Type
Click "OK".
Select "Apply" from the "Actions" pane.
STIG Reference
- STIG
- Microsoft IIS 10.0 Site Security Technical Implementation Guide
- Version
- 2
- Release
- 15
- Rule ID
- SV-218742r1022679_rule
All Occurrences
This vulnerability appears on 2 ship(s)
| Ship | Hull # | Source File | Status | Assigned To | Scan Date | Actions |
|---|---|---|---|---|---|---|
| LAB BASELINES | BASELINE | SCHR-P3-DP-001_IIS10Site_Default_Web_Site_V2R14_20260305-133115.cklb | Unassigned | 2026-03-12T15:38:14.459023 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_IIS10Site_Default_Web_Site_V2R12_20251023-143912.ckl | Unassigned | 2026-01-14T12:57:35.375369 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Exchange_Back_End_V2R12_20251023-152602.ckl | Unassigned | 2026-01-14T12:57:33.300070 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Default_Web_Site_V2R12_20251023-152518.ckl | Unassigned | 2026-01-14T12:57:33.098574 | View in Context |