Talk With an Expert

Securing an Existing IIS 5.0 DMZ Infrastructure

Securing an Existing IIS 5.0 DMZ Infrastructure (PDF, 1.85MB)Published: 25 Jul, 2004
Created by:
Julius Fitzgerald

The task of designing a secure infrastructure for IIS 5.0 web servers within a DMZ is difficult enough. Securing an existing DMZ becomes exponentially more difficult due to the added requirement of retrofitting those currently working servers with more appropriate security settings, policies and operational procedures while not adversely affecting website or application availability and keep costs to a minimum throughout the process. The purpose of this writing is to outline the steps I took to obtain management approval to review the existing security settings and procedures within the DMZ Web Hosting Operations infrastructure, prepare a strategy for implementing additional security measures with minimal service impact, and outline additional security best practices our company implemented for maintaining the new security posture. The environment referenced for this writing consists primarily of Windows 2000, SP4, IIS 5.0 web servers with the latest security rollup patches and hotfixes.