Skip to content

Directory Browsing on the IIS 10.0 web server must be disabled.

An XCCDF Rule

Description

Directory browsing allows the contents of a directory to be displayed upon request from a web client. If directory browsing is enabled for a directory in IIS, users could receive a web page listing the contents of the directory. If directory browsing is enabled, the risk of inadvertently disclosing sensitive content is increased.

ID
SV-218808r961158_rule
Version
IIST-SV-000138
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Open the IIS 10.0 Manager.

Click the IIS 10.0 web server name.

Double-click the "Directory Browsing" icon.