Skip Navigation

IIST-SV-000138: Disable directory browsing

Directory Browsing on the IIS 10.0 web server must be disabled.
To check compliance with IIST-SV-000138, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    Directory Browsing
    icon.
  4. Under
    Log Event Destination
    , verify that the
    Both log file and ETW event
    option is selected.
  5. In the
    Actions
    panel, verify that
    Directory Browsing
    is disabled.
If
Directory Browsing
is enabled, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    Directory Browsing
    icon.
  4. In the
    Actions
    pane, click
    Disabled
    .