6.10 Ensure HTTP Server is not enabled

Information

HTTP or web servers provide the ability to host web site content.

*Rationale*

Unless there is a need to run the system as a web server, it is recommended that the
package be deleted to reduce the potential attack surface.

Solution

Remove any start links for apache2 from /etc/rc*.d-# rm /etc/rc*.d/S*apache2

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: b1e077784b334c198b92e483e289f10abe7206734dc5a5b551dec71be722e829