Below you will find the reply from the NSA about the IIS security document. It is obvious that the document was a draft and NSA is now making the final document available for download.
Read the full story by clicking on Read More below.
As a follow-up to our original post yesterday we wanted to publicly commend the NSA for their quick and open response to our commentary.
Bill Walker, the author, explained that the document that was posted on
their web site was a draft that was written on March 2001 and not the final version. He explained that the old document had mistakingly been posted. The new version will be placed on their web site when it is back up. In the meantime you can get the new document (796kb) at these locations:
http://www.xato.net/downloads/SecureIIS5.zip
http://www.iisanswers.com
The new document addresses several of the issues we brought up. Bill has stated that he will be addressing other issues as well in future revisions. We were very pleased with Bill's openness to our criticism and his efforts to improve the document.
We regret that our commentary singled our this author, but we felt strongly that a public criticism was necessary. Although we do not expect the NSA to get into the document publishing business, we hope they will put more resources towards this effort. Nonetheless, we do expect these documents to be a valuable resource as they evolve.
.sozni
Xato Network Security
www.xato.net