1.3.2 Turn Debug Off

Information

Setting <compilation debug> to false ensures that detailed error information does not inadvertently display during live application usage, mitigating the risk of application information leakage falling into unscrupulous hands.

Solution

To use the UI to make this change: Open IIS Manager and navigate desired server, site, or application In Features View, double-click .NET Compilation On the .NET Compilation page, in the Behavior section, ensure the Debug field is set to False When finished, click Apply in the Actions pane Note: The <compilation debug> switch will not be present in the web.config file unless it has been added manually, or has previously been configured using the IIS Manager GUI.

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11

Plugin: Windows

Control ID: fddb35c943ff1403be4550f1e404ccc2abdd38cacb58fc89e844a4ea93fa2591