1.3.1 Set Deployment Method to Retail

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Utilizing the switch specifically intended for production IIS servers will eliminate the risk of vital application and system information leakages that would otherwise occur if tracing or debug were to be left enabled, or customErrors were to be left off.

Solution

Open the machine.config file located in: %windir%\Microsoft.NET\Framework\<framework_version>\CONFIG Add the line <deployment retail='true' /> within the <system.web> section If systems are 64-bit, do the same for the machine.config located: %windir%\Microsoft.NET\Framework64\<framework_version>\CONFIG

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 4916cfb026413c7dcb62217276c83fc38093ebcb6645117961951b83afd0215b