RHEL-07-020110 - The Red Hat Enterprise Linux operating system must disable the file system automounter unless required.

Information

Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity.

Satisfies: SRG-OS-000114-GPOS-00059, SRG-OS-000378-GPOS-00163, SRG-OS-000480-GPOS-00227

Solution

Configure the operating system to disable the ability to automount devices.

Turn off the automount service with the following commands:

# systemctl stop autofs
# systemctl disable autofs

If 'autofs' is required for Network File System (NFS), it must be documented with the ISSO.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

References: 800-53|CM-6b., 800-53|IA-3, CAT|II, CCI|CCI-000366, CCI|CCI-000778, CCI|CCI-001958, Rule-ID|SV-204451r853893_rule, STIG-ID|RHEL-07-020110, STIG-Legacy|SV-86609, STIG-Legacy|V-71985, Vuln-ID|V-204451

Plugin: Unix

Control ID: 61469c2ee9b20d25854a6aa140246b5d685749acc5dd828ffd5c5db03b827150