2.2.3 Ensure CUPS is not enabled

Information

The Common Unix Print System (CUPS) provides the ability to print to both local and network printers. A system running CUPS can also accept print jobs from remote systems and print them to local printers. It also provides a web based remote administration capability.

Rationale:

If the system does not need to print jobs or accept print jobs from other systems, it is recommended that CUPS be disabled to reduce the potential attack surface.

Impact:

Disabling CUPS will prevent printing from the system, a common task for workstation systems.

Solution

Run one of the following commands to disable cups :

# systemctl --now disable cups

See Also

https://workbench.cisecurity.org/files/2970

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: a8e2a4f4582dd9e216ab485412466553656fee6208b22eaa27737ffc2c3674d8