1.1.9 Disable Automounting

Information

autofs allows automatic mounting of devices, typically including CD/DVDs and USB drives.

Rationale:

With automounting enabled anyone with physical access could attach a USB drive or disc and have its contents available in the filesystem even if they lacked permissions to mount it themselves.

Impact:

The use of portable hard drives is very common for workstation users. If your organization allows the use of portable storage or media on workstations and physical access controls to workstations are considered adequate there is little value add in turning off automounting.

Solution

If there are no other packages that depends on autofs, remove the package with:

# apt purge autofs

-OR- if there are dependencies on the autofs package:
Run the following commands to mask autofs:

# systemctl stop autofs
# systemctl mask autofs

See Also

https://workbench.cisecurity.org/benchmarks/13007

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-7, CSCv7|8.5

Plugin: Unix

Control ID: b41ec18ca518349179ad2ad027055ef55fbb20d3f0f713d35b617d7240bdc569