This technical report provides an analysis of the hisecweb security template used for securing Internet Information Services (IIS) on Windows 2000. It outlines the default security settings in Windows 2000 and IIS 5.0, emphasizing that many settings are disabled by default, which simplifies the security task. The report details the assumptions made when applying the hisecweb template, such as the server being a dedicated web server and not part of a domain. It also describes the importance of analyzing the changes made by the template and recommends backing up the system before implementation. The report categorizes the security policy settings into account policies, event log settings, local security policies, changes to services, and additional registry changes. Each category is detailed with specific settings, including password policies, account lockout policies, and local policies, providing a comprehensive understanding of the security measures involved.