If ACLs are setup fine on server's drive root and its definately possible to stop shell scripts like c99 and r57.
Running each site under its own app pool adds more security to it.
Rubal Jain // Email - Rubal @ Rubal [dot] Net
Windows Server Setup, Configuration, Troubleshooting, Basic Security & Hardening
DotNetPanel - Helm Control Panel Setup, Installation, Configuration, Troubleshooting
Server setup includes installation of PHP, Perl, Python, ASP.Net Frameworks, SQL Express, MySQL etc and complete integration with control panel.
Authorised DNP Reseller. Get 20% Discount on all DNP Licenses
Authorised SmarterTools, Declude, SimpleDNS (JHSoft), Gene6 FTP, Helicon, Kayako, Icewarp Merak, MailEnable, Deerfield Reseller.