1.1.9 Disable Automounting

Information

autofs allows automatic mounting of devices, typically including CD/DVDs and USB drives.

With automounting enabled anyone with physical access could attach a USB drive or disc and have its contents available in system even if they lacked permissions to mount it themselves.

Solution

If there are no other packages that depends on autofs remove the package with:

# dnf remove autofs

Run the following command to disable autofs if it is required:

# systemctl --now disable autofs

Impact:

The use of portable hard drives is very common for workstation users. If your organization allows the use of portable storage or media on workstations and physical access controls to workstations is considered adequate there is little value add in turning off automounting.

See Also

https://workbench.cisecurity.org/files/3796

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-7, CSCv7|8.5

Plugin: Unix

Control ID: 6ad598772bf0a2fec5013e7bf71db43056757c4dba9dfe9cec5ea08321b4760b