GEN008640 - The system must not use removable media as the boot loader - 'service'

Information

Malicious users with removable boot media can gain access to a system configured to use removable media as the boot loader.

Solution

Configure the system to use a bootloader installed on fixed media.
# bootlist -m normal hdisk0
# bootlist -m service hdisk0

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-38837r1_rule, STIG-ID|GEN008640, Vuln-ID|V-4247

Plugin: Unix

Control ID: 503622f5809d65fe8f2690652985f4e3885f860330d1ec1936ed736cd7b1d3de