2.2.4 Ensure CUPS is not enabled

Information

The Common Unix Print System (CUPS) provides the ability to print to both local and network printers. A system running CUPS can also accept print jobs from remote systems and print them to local printers. It also provides a web based remote administration capability.

Rationale:

If the system does not need to print jobs or accept print jobs from other systems, it is recommended that CUPS be disabled to reduce the potential attack surface.

Solution

Run the following command to disable cups:

# systemctl disable cups

Impact:

Disabling CUPS will prevent printing from the system, a common task for workstation systems.

References:

More detailed documentation on CUPS is available at the project homepage at http://www.cups.org.

See Also

https://workbench.cisecurity.org/files/2619

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 81d77ff40a3ecc19edec1f261cdacd1ac86d63d92a00b9d28a768e261d6904c4