1.1.9 Ensure autofs is not installed or the autofs service is disabled

Information

autofs allows automatic mounting of devices, typically including CD/DVDs and USB drives.

With automounting enabled anyone with physical access could attach a USB drive or disc and have its contents available in the filesystem even if they lacked permissions to mount it themselves.

Solution

If there are no other packages that depends on autofs remove the package with:

# apt purge autofs

-OR- if there are dependencies on the autofs package:

Run the following commands to mask autofs :

# systemctl stop autofs
# systemctl mask autofs

Impact:

The use of portable hard drives is very common for workstation users. If your organization allows the use of portable storage or media on workstations and physical access controls to workstations are considered adequate there is little value add in turning off automounting.

See Also

https://workbench.cisecurity.org/benchmarks/15023

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-7, CSCv7|8.5

Plugin: Unix

Control ID: 048a1f6b5c9291ca7385defc7e1d94ad72cb4c25391292b30fe16c34d0707573