139
The
World
Wide Web Publishing Service
provides Web connectivity and administration of Web sites
through the IIS snap-in. The
World Wide Web Publishing Service
must be running for an IIS server to
provide Web connectivity and administration through the IIS Manager. Using Group Policy to secure
and set the startup mode of a service grants access solely to server administrators, thus preventing the
service from being configured or operated by unauthorized or malicious users. The Group Policy will
also prevent administrators from inadvertently disabling the service. For these reasons, the
World
Wide Web Publishing Service
setting is configured to
Automatic
for IIS servers in all three
environments defined in this guide.
2.11.6
Additional Security Settings
After installing Windows Server 2003 and IIS, IIS by default transmits only static Web content. When
Web sites and applications contain dynamic content, or require one or more additional IIS
components, each additional IIS feature must be individually enabled. However, care should be
taken during this process to ensure that the attack surface of each IIS server on the network is
minimized. If the company Web sites are comprised of static content and do not require any other IIS
components, then the default IIS configuration is sufficient to minimize the attack surface of the IIS
servers on the network. The security settings applied through the MSBP provide a great deal of
enhanced security for IIS servers. Nevertheless, there are a few additional considerations and
procedures that should be taken into account. These steps cannot be completed via Group Policy and
should be performed manually on all IIS servers.