2.2.10 Ensure HTTP server is not enabled

Information

HTTP or web servers provide the ability to host web site content.

Rationale:

Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

Solution

Run the following command to disable apache2:

# systemctl disable apache2

See Also

https://workbench.cisecurity.org/files/2619

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: f2352c5b354569e00b2977a8fa29dbe4cacbac6cdcf55fef03f44b26a6d2b8e6