IIS server hardening steps:
Check Step Notes:
Check Procedure record:
Install and configure Windows Server 2003.
Install configurationsServer2003
Install and configure IIS services:
Install only necessary IIS components.
Enable only essential web service extensions.
Place content on a dedicated disk volume.
Configure NTFS permissions.
Configure IIS web site permissions.
Configure IIS logging.
Install configurationsIISService:
Only install requiredIISComponents
Only enable requiredWeb ServiceExtended item
Put (website) content in a separate disk volume
ConfigurationNTFSPermission
ConfigurationIISWebsite Permissions
ConfigurationIISLogs
Apply any required service packs and/or updates.
Apply any patch packages or updates required
Install and configure a virus protection solution.
Install and configure a virus protection solution
Install and configure mom agents or similar monitoring solution as required.
Install and configure if necessaryMom agentOr similar monitoring Solution
Move appropriate server to the corresponding IIS servers ou.
Move the appropriate server to the correspondingIISServer organizational unit
Secure well-known accounts.
SetWell-knownAccount(??)Security
Rename the built-in Administrator Account, assign a complex password. Ensure Guest account is disabled. Change default account description.
Rename the built-inAdministratorAccount and set a complex password. EnsureGuestThe account has been disabled. Modify the default account description.
Secure Services accounts.
Set service account Security
Consider implementing IPSec filters.
Application considerationsIPSecFilter
Verify incremental IIS server policy has replicated between domain controllers.
Verify the newly addedIISThe server policy has been copied between multiple domain controllers.
Run gpupdate. EXE/force.
RunGpupdate. EXE/Force
Restart the server.
Restart the server
Check the Event Logs for errors.
Check Event Log check errors