Securing Windows Server 2003 tasks
Cisco TMS Secure Server Configuration Guide 13.0
Page 15 of 34
Component
Subcomponent
Include
Windows Media Services
N
Table 3 IIS components
Component
Subcomponent
Include
Background Intelligent Transfer
Service (BITS) Server Extensions
N
Common Files
Y
File Transfer Protocol (FTP) Service
N
FrontPage 2002 Server Extensions
N
Internet Information Services Manager
Y
Internet Printing
N
NNTP Service
N
SMTP
N
World Wide Web Services
Active Server Pages
Y
Internet Data Connector
N
Remote Administration (HTML)
N
Remote Desktop Web Connection
N
Serve Side Includes
N
WebDAV Publishing
N
World Wide Web Service
Y
Disable unnecessary windows services
To reduce the attack surface of the Cisco TMS server, all Windows Services that are not required by
Cisco TMS should in general be disabled.
Go to Windows Start > Control Panel > Administrative Tools >Services.
Disable the services in the following list.
1.
Right-click each of them.
2.
Under the General tab, click Properties and select Disabled for Startup type.
The status should then be displayed as Disabled under the Status column in the list of Windows
services.
Alerter
Portable Media Serial Number Service
Application Experience Lookup Service
Print Spooler
Application Layer Gateway Service
Remote Access Auto Connection Manager
Application Management
Remote Desktop Help Session Manager
Automatic Updates
Remote Procedure Call (RPC) Locator
Background Intelligent Transfer Service
Remote Registry
ClipBook
Resultant Set of Policy Provider
COM+ System Application
Routing and Remote Access