2.2.10 Ensure HTTP server is not enabled

Information

HTTP or web servers provide the ability to host web site content. Unless there is a need to run the system as a web server, it is recommended that the package be deleted to reduce the potential attack surface.

Solution

Run the following command to disable apache2: # systemctl disable apache2

See Also

https://workbench.cisecurity.org/files/1866

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 14d761f126d803b5df99a155a9e872a5f97679924978d6fdac68a78a7b5a3b77