OL09-00-000020 - OL 9 must be configured so that the graphical display manager is not the default target unless approved.

Information

Unnecessary service packages must not be installed to decrease the attack surface of the system. Graphical display managers have a long history of security vulnerabilities and must not be used unless approved and documented.

Solution

Configure OL 9 to boot to the command line.

Set the default target to multi-user with the following command:
$ sudo systemctl set-default multi-user.target

If there is an operational requirement for a graphical user interface, document it with the ISSO.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-271440r1092462_rule, STIG-ID|OL09-00-000020, Vuln-ID|V-271440

Plugin: Unix

Control ID: f426d4a6bcab82f593f3df420df00043d94822c7ea06cadefd86fc1810c5bcbe