6.10 Ensure HTTP Server is not enabled

Information

HTTP or web servers provide the ability to host web site content. Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

Solution

Disable apache2- # update-rc.d apache2 disable

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 80eaa4904c23bcb8d9f0cfc27d3dbe7fb7ffd5556b280839c3da87ee111ab334