2.1.7 Disable USB Firmware and configuration installation

Information

Disable USB port auto install feature for config and firmware.

Disabling USB port for auto install prevents a USB with a manipulated configuration or incorrect firmware from being connected and loaded automatically.

Solution

CLI:

config system auto-install
set auto-install-config disable
set auto-install-image disable
end

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|11.3

Plugin: FortiGate

Control ID: fbf41eb809375053debf00193febfa97d615c73c29e367c3d2092c362cb5c423