1.3.1 Set Deployment Method to Retail

Information

Utilizing the switch specifically intended for production IIS servers will eliminate the risk of vital application and system information leakages that would otherwise occur if tracing or debug were to be left enabled, or customErrors were to be left off.

Solution

Open the machine.config file located in: %windir%\Microsoft.NET\Framework\<framework_version>\CONFIG Add the line <deployment retail='true' /> within the <system.web> section If systems are 64-bit, do the same for the machine.config located: %windir%\Microsoft.NET\Framework64\<framework_version>\CONFIG

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 4916cfb026413c7dcb62217276c83fc38093ebcb6645117961951b83afd0215b