4.2.2 Ensure NIS client is not installed

Information

If NIS is not used in the environment, disable the NIS client and de-install the software.

As NIS is extremely insecure, the NIS client packages must be removed from the system unless absolutely needed.

Solution

Ensure that all of the NIS daemons are inactive:

stopsrc -g yp

De-install the NIS client software:

installp -u bos.net.nis.client

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: acf50fd9cd807b24abe32499a0899abd667d9e946d6b57f46608cc5be7b3ef27