Security.com

Windows IIS server hardening checklist

By Michael Cobb

Default configurations for most OSes are not designed with security as the primary focus. Rather, they concentrate on ease of setup, use and communications. Therefore, web servers running default configurations are obvious targets for automated attacks and can be quickly compromised.

Device hardening is the process of enhancing web server security through a variety of measures to minimize its attack surface and eliminate as many security risks as possible in order to achieve a much more secure OS environment.

Because web servers are constantly attached to the internet and often act as gateways to an organization's critical data and services, it is essential to ensure they are hardened before being put into production.

Consult this server hardening checklist to ensure server hardening policies are correctly implemented for your organization's Windows Internet Information Services (IIS) server.

General

Windows IIS server hardening

Download a PDF copy of this page for an easy-to-use checklist.

Accounts

Files and directories

Shares

Ports

Registry

Auditing and logging

Sites and virtual directories

Script mappings

ISAPI filters

IIS Metabase

Server certificates

Machine.config

27 Feb 2020

All Rights Reserved, Copyright 2000 - 2024, TechTarget | Read our Privacy Statement