2.1.10 Ensure HTTP server is not enabled - status

Information

HTTP or web servers provide the ability to host web site content.

Rationale:

Unless there is a need to run the system as a web server, it is recommended that the service be disabled to reduce the potential attack surface.

Solution

Run the following command to disable httpd :

# systemctl disable httpd

# systemctl stop httpd

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Unix

Control ID: 9bf031713db6b486b9013fd0aafca26e5f491346a79892e4f25c48a06c0ba3e1