20.64 Ensure 'TFTP Client' is 'not installed' (STIG only)

Information

This setting provides the transfer of files to and from a remote computer, typically a computer running UNIX, that is running the Trivial File Transfer Protocol (tftp) service or daemon. tftp is typically used by embedded devices or systems that retrieve firmware, configuration information, or a system image during the boot process from a tftp server.

The STIG recommended state for this setting is: Not installed

Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system.

Solution

To Uninstall the

TFTP Client

feature:

- Start 'Server Manager'
- Select the server with the role
- Scroll down to 'ROLES AND FEATURES' in the right pane
- Select 'Remove Roles and Features' from the drop-down 'TASKS' list
- Select the appropriate server on the 'Server Selection' page and click 'Next'
- Deselect 'TFTP Client' on the 'Features' page
- Click 'Next' and 'Remove' as prompted (if installed).

Impact:

Trivial File Transfer Protocol (tftp) features, such as the transferring of files, will not be available to users in your organization.

See Also

https://workbench.cisecurity.org/benchmarks/20002

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 2455aeabca422cf3c3f5160d868bd0ee4c1f3d67d702a03b5a18383d4e718988