6.7 Ensure that the REST API is disabled

Information

The net.http.RESTInterfaceEnabled parameter is used to enable or disable the REST API. Enabling this parameter also enables the HTTP interface, even if the parameter for enabling the HTTP interface is set to disabled.

Please note that this function has been Deprecated since version 3.2.

Rationale:

Additional interfaces expose the system to a greater extent. Running unnecessary services may allow an attacker to penetrate the system via an unknown vulnerability.

Solution

Set the parameter value to false to disable the REST API.

Default Value:

false

See Also

https://workbench.cisecurity.org/files/168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: d56c7544be562d71b3fc8ff4cb325860e7bd4a5c9126a990ab79d70ba310bfc7