Directory Browsing on the IIS 10.0 web server must be disabled.
An XCCDF Rule
Description
Directory browsing allows the contents of a directory to be displayed upon request from a web client. If directory browsing is enabled for a directory in IIS, users could receive a web page listing the contents of the directory. If directory browsing is enabled, the risk of inadvertently disclosing sensitive content is increased.
- ID
- SV-218808r961158_rule
- Version
- IIST-SV-000138
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Double-click the "Directory Browsing" icon.