Skip Navigation

IIST-SI-000231: Disable directory browsing

Directory Browsing on the IIS 10.0 website must be disabled.
To check compliance with IIST-SI-000231, complete the following steps for each site hosted on the IIS 10.0 web server:
  1. Open the IIS 10.0 Manager.
  2. Click the website name.
  3. Double-click the
    Directory Browsing
    icon. If Directory Browsing is not installed, this is not applicable.
  4. In the
    Actions
    pane, verify that
    Directory Browsing
    is
    Disabled
    .
If the
Directory Browsing
option is not Disabled, your application is not compliant.
If your application is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the site name.
  3. Double-click the
    Directory Browsing
    icon.
  4. In the
    Actions
    pane, click
    Disabled
    .