Skip Navigation
 Search | Directories | Reference Tools
UW Home > UWIN > Computing and Networking > Support > UW Domains 

IIS Security Checklist

The following checklist is a summary of the security points which should be checked prior to bringing an IIS server online. In cases where these points are not followed, the admin may want to securely document the known security issues for referral should a security compromise occur.

General assumptions:

Design Guidelines

Installation configuration

Patch level

Authentication model:

Authorization Changes

Re-used with permission from Stanford University for which I originally wrote this documentation, http://windows.stanford.edu/docs/IISsecchecklist.htm