4.6 Custom Errors - 'defaultRedirect'

Information

Enabling this property will send a generic message to the user in the event of an error and not leak information. NOTE: This check audits the default system drive. If your organization's configuration is different the '%systemdrive%' variable will need to be adjusted. NOTE2: Change <framework_version> to the version of .NET that is in use by your organization. NOTE3: Change <PATH> to the directory path to your custom error page.

Solution

Make sure 'Custom Errors defaultRedirect' is set to redirect to a custom error page.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11

Plugin: Windows

Control ID: c6c835b444e834868d58c5dee5747f071926abe5ce18f7efc196a73043a55e7f