2.2.3 Ensure CUPS is not installed

Information

The Common Unix Print System (CUPS) provides the ability to print to both local and network printers. A system running CUPS can also accept print jobs from remote systems and print them to local printers. It also provides a web based remote administration capability.

Rationale:

If the system does not need to print jobs or accept print jobs from other systems, it is recommended that CUPS be removed to reduce the potential attack surface.

Impact:

Removing CUPS will prevent printing from the system, a common task for workstation systems.

Solution

Run one of the following commands to remove cups :

# apt purge cups

See Also

https://workbench.cisecurity.org/benchmarks/13775

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: e77b68d3d4e7491fac4ffa52ff42319de586816e68082774ec313c90f481e038