5.5 Ensure 'Simple TCP/IP Services (simptcp)' is set to 'Not Installed'

Information

This policy setting supports the following TCP/IP services: Character Generator, Daytime, Discard, Echo, and Quote of the Day.

The STIG recommended state for this setting is: Not Installed

Note: This service is not installed by default. It is supplied with Windows, but is installed by enabling an optional Windows feature (

Simple TCPIP services (i.e. echo, daytime etc)

).

The Simple TCP/IP Services have very little purpose in a modern enterprise environment - allowing them might increase exposure and risk for attack.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled or ensure the service is not installed.

Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Simple TCP/IP Services

OR

To Uninstall the

Simple TCP/IP Services (simptcp)

feature:

- Start 'Server Manager'
- Select the server with the role
- Scroll down to 'ROLES AND FEATURES' in the right pane
- Select 'Remove Roles and Features' from the drop-down 'TASKS' list
- Select the appropriate server on the 'Server Selection' page and click 'Next'
- Deselect 'Simple TCP/IP Services' on the 'Features' page
- Click 'Next' and 'Remove' as prompted (if installed).

Impact:

The Simple TCP/IP services (Character Generator, Daytime, Discard, Echo and Quote of the Day) will not be available.

See Also

https://workbench.cisecurity.org/benchmarks/15301

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: ef11d841fc589186622c916e9b3a1cda5796c724b59acbdf52a5c9dbdb039a11