---
title: Security checklist - deploying a website
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

This is a security deployment checklist – things to do before you [deploy your site](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment.md) to a live environment.

### Web.config:

| Check | Description                                                                                                                                       | Details                                                                                                                                                                         |
| ----- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|       | The debug mode is turned off to prevent sensitive information leakage.                                                                            | [Web.config file settings](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment/web-config-file-settings.md)                                |
|       | Tracing is disabled to prevent sensitive information leakage.                                                                                     | [Web.config file settings](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment/web-config-file-settings.md)                                |
|       | The error messages of websites and application-server default error messages are not displayed in details to users.                               | [Designing secure error messages](https://docs.kentico.com/k8/securing-websites/developing-secure-websites/handling-error-messages-securely/designing-secure-error-messages.md) |
|       | Sensitive sections of the web.config file are encrypted (mainly the connection string).                                                           | [How To: Encrypt Configuration Sections in ASP.NET 2.0 Using DPAPI](http://msdn.microsoft.com/en-us/library/ff647398.aspx)                                                      |
|       | Access to sensitive directories is forbidden to protect the servers against the enumeration attack.                                               | [Enumeration](https://docs.kentico.com/k8/securing-websites/developing-secure-websites/enumeration.md)                                                                          |
|       | Cookieless authentication is disabled to prevent session hijacking. This can be done by changing the cookieless attribute of the form element.    | [Session protection](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-and-protecting-the-system/session-protection.md)                          |
|       | The _HttpOnlyCookies_ flag is set so that the cookies are accessible only from the server-side code (this behavior is set by default in Kentico). | [Web.config file settings](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment/web-config-file-settings.md#cookies)                        |

### IIS:

| Check | Description                                                                                                                                              | Details                                                                                                                                                              |
| ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|       | Directory listing is disabled in the website and web servers.                                                                                            | [Export/import package directory browsing](https://docs.kentico.com/k8/deploying-websites/exporting-and-importing-sites/export-import-package-directory-browsing.md) |
|       | All HTTP methods except GET and POST are disabled if they are not in use.                                                                                | [Securing the Staging and REST web services](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-the-staging-and-rest-web-services.md)  |
|       | Scripts and 3rd party libraries are up-to-date. If external libraries (e.g. for database access, XML parsing) are used, always use the current versions. |                                                                                                                                                                      |
|       | Sensitive links which should not be indexed by search engines are listed within robots.txt files.                                                        | [Managing robots.txt](https://docs.kentico.com/k8/configuring-kentico/search-engine-optimization/managing-robots-txt.md)                                             |
|       | The execution of scripts is disabled on folders where it is undesirable.                                                                                 | [Edit Feature Permissions for the Handler Mappings Feature (IIS 7)](http://technet.microsoft.com/en-us/library/cc725855%28v=ws.10%29.aspx)                           |

### Kentico:

| Check | Description                                                                                                                                                                                                     | Details                                                                                                                                                                                                                                                  |
| ----- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|       | All test user accounts are deleted or disabled.                                                                                                                                                                 |                                                                                                                                                                                                                                                          |
|       | All unnecessary modules and applications are disabled.                                                                                                                                                          | [Disabling unnecessary modules and services and keeping the system up-to-date](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment/disabling-unnecessary-modules-and-services-and-keeping-the-system-up-to-date.md) |
|       | All unnecessary pages are deleted.                                                                                                                                                                              |                                                                                                                                                                                                                                                          |
|       | File types that can be uploaded to the system are restricted. You can specify which extensions are allowed for uploaded files in general, including forms in Settings -> System -> Files in the Security group. |                                                                                                                                                                                                                                                          |
|       | UI personalization for specified roles is set correctly to prevent users from accessing unnecessary user interface. You can configure UI personalization in the UI personalization application.                 | [UI Personalization](https://docs.kentico.com/k8/managing-users/ui-personalization.md)                                                                                                                                                                   |
|       | Permissions for specified actions in Kentico modules are set correctly for all roles. You can configure permissions in the Permissions application.                                                             | [Configuring permissions securely](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/configuring-permissions-securely.md)                                                                                                          |
|       | Users are allowed to use only strong and complex passwords. You can enable the Use password policy setting in Settings -> Security & Membership -> Passwords.                                                   | [Password strength policy and its enforcement](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/password-strength-policy-and-its-enforcement.md)                                             |
|       | The passwords are stored in a strong and secure format. Recommended option is SHA2 with salt. You can set password format in Settings -> Security & Membership -> Passwords -> general group.                   | [Setting the user password format](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/setting-the-user-password-format.md)                                                                     |
|       | The number of allowed invalid logon attempts is limited. You can set the limit in Settings -> Security & Membership -> protection in the Invalid logon attempts group.                                          | [Invalid logon attempts](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-user-accounts-and-passwords/invalid-logon-attempts.md)                                                                                         |
|       | You have consider if autocomplete function is needed. Autocomplete can be enabled in Settings -> Security & Membership -> Protection -> General group.                                                          | [Autocomplete deactivation](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-and-protecting-the-system/autocomplete-deactivation.md)                                                                                     |
|       | Forms are secured with CAPTCHA (spam protection control).                                                                                                                                                       | [Spam protection (CAPTCHA)](https://docs.kentico.com/k8/securing-websites/designing-secure-websites/securing-and-protecting-the-system/spam-protection-captcha.md)                                                                                       |
|       | Encrypted Internet connection (HTTPS) is configured properly.                                                                                                                                                   | [Configuring SSL](https://docs.kentico.com/k8/securing-websites/deploying-websites-to-a-secure-environment/configuring-ssl.md)                                                                                                                           |
