---
title: Security checklist - deploying a website
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

This is a security deployment checklist – things to do before you [deploy your site](https://docs.kentico.com/13/securing-websites/deploying-websites-to-a-secure-environment.md) to a live environment.

### Web.config:

| Check | Description                                                                                                                            | Details                                                                                                                                                                                         |
| ----- | -------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|       | Debug mode is turned off to prevent leaks of sensitive information.                                                                    | [Web.config security settings](https://docs.kentico.com/13/securing-websites/deploying-websites-to-a-secure-environment/web-config-security-settings.md#error-messages-and-disabling-the-debug) |
|       | The error messages of websites and application-server default error messages do not display detailed information to users.             | [Designing secure error messages](https://docs.kentico.com/13/securing-websites/developing-secure-websites/handling-error-messages-securely/designing-secure-error-messages.md)                 |
|       | Sensitive sections of the configuration file are encrypted (mainly the connection string).                                             | [Encrypting and Decrypting Configuration Sections](https://docs.microsoft.com/en-us/previous-versions/aspnet/zhhddkxy\(v=vs.100\))                                                              |
|       | Access to sensitive directories is forbidden to protect the servers against enumeration attacks.                                       | [Enumeration](https://docs.kentico.com/13/securing-websites/developing-secure-websites/enumeration.md)                                                                                          |
|       | Cookieless authentication is disabled to prevent session hijacking.                                                                    | [Session protection](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-and-protecting-the-system/session-protection.md)                                          |
|       | The _HttpOnlyCookies_ flag is set so that the cookies are accessible only from the server-side code (this behavior is set by default). | [Web.config security settings](https://docs.kentico.com/13/securing-websites/deploying-websites-to-a-secure-environment/web-config-security-settings.md#cookies)                                |

### IIS:

| Check | Description                                                                                                                                              | Details                                                                                                                                                                                    |
| ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|       | Directory listing is disabled in the website and web servers.                                                                                            | [Export/import package directory browsing](https://docs.kentico.com/13/deploying-websites/exporting-and-importing-sites/export-import-package-directory-browsing.md)                       |
|       | All HTTP methods except GET and POST are disabled if they are not in use.                                                                                | [Securing the Staging and REST web services](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-the-staging-and-rest-web-services.md)                        |
|       | Scripts and 3rd party libraries are up-to-date. If external libraries (e.g. for database access, XML parsing) are used, always use the current versions. |                                                                                                                                                                                            |
|       | Sensitive links which should not be indexed by search engines are listed within robots.txt files.                                                        |                                                                                                                                                                                            |
|       | The execution of scripts is disabled on folders where it is undesirable.                                                                                 | [Edit Feature Permissions for the Handler Mappings Feature (IIS 7)](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc725855\(v=ws.10\)) |

### Xperience:

| Check | Description                                                                                                                                                                                                                | Details                                                                                                                                                                                                                          |
| ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|       | All test user accounts are deleted or disabled.                                                                                                                                                                            |                                                                                                                                                                                                                                  |
|       | All unnecessary features and applications are disabled.                                                                                                                                                                    | [Disabling unnecessary services and keeping the system up-to-date](https://docs.kentico.com/13/securing-websites/deploying-websites-to-a-secure-environment/disabling-unnecessary-services-and-keeping-the-system-up-to-date.md) |
|       | All unnecessary pages are deleted.                                                                                                                                                                                         |                                                                                                                                                                                                                                  |
|       | File types that can be uploaded to the system are restricted. You can specify which extensions are allowed for uploaded files in general, including forms in _Settings -> System -> Files_ in the _Security_ category.     |                                                                                                                                                                                                                                  |
|       | UI personalization for specified roles is set correctly to prevent users from accessing unnecessary parts of the interface. You can configure UI personalization in the _UI personalization_ application.                  | [UI Personalization](https://docs.kentico.com/13/managing-users/ui-personalization.md)                                                                                                                                           |
|       | Permissions for specified actions in Xperience modules are set correctly for all roles. You can configure permissions in the _Permissions_ application.                                                                    | [Configuring permissions securely](https://docs.kentico.com/13/securing-websites/designing-secure-websites/configuring-permissions-securely.md)                                                                                  |
|       | Users are allowed to use only strong and complex passwords. You can enable the Use password policy setting in _Settings -> Security & Membership -> Passwords_.                                                            | [Password strength policy and its enforcement](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/password-strength-policy-and-its-enforcement.md)                     |
|       | Passwords are stored in a strong and secure format. The recommended option is PBKDF2. You can set the password format in Settings -> Security & Membership -> Passwords -> Password format.                                | [Setting the user password format](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/setting-the-user-password-format.md)                                             |
|       | The number of allowed invalid sign-in attempts is limited. You can set the limit for the administration interface in _Settings -> Security & Membership -> Protection_ in the _Invalid sign-in attempts_ category.         | [Invalid sign-in attempts](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/invalid-sign-in-attempts.md)                                                             |
|       | You have considered if the autocomplete function is needed for sign-in forms. Autocomplete can be enabled for the administration interface in _Settings -> Security & Membership -> Protection_ in the _General_ category. | [Autocomplete deactivation](https://docs.kentico.com/13/securing-websites/designing-secure-websites/securing-and-protecting-the-system/autocomplete-deactivation.md)                                                             |
|       | Forms are secured with CAPTCHA (spam protection control).                                                                                                                                                                  | [Reference - System form components](https://docs.kentico.com/13/developing-websites/form-builder-development/reference-system-form-components.md)                                                                               |
|       | Encrypted connection (HTTPS) is configured properly.                                                                                                                                                                       | [Configuring SSL](https://docs.kentico.com/13/securing-websites/deploying-websites-to-a-secure-environment/configuring-ssl.md)                                                                                                   |
