3.4 (L1) Host must deactivate SLP

Information

The Service Location Protocol (SLP) is used for the discovery and selection of network services in local area networks, which simplifies configuration by allowing computers to find necessary services automatically. The practice of deactivating SLP when not in use aligns with the principle of minimizing the attack surface by shutting down non-essential services. The recommended setting is to have the SLP service stopped, with the ability to start and stop it manually as required.

Deactivating non-essential services like SLP minimizes potential vectors of attack, thereby enhancing the host's security posture.

Solution

Impact:

There is no functional impact noted, however, manual intervention is required to start the SLP service when needed.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: VMware

Control ID: e725c4aa06b68f752381dc99be9511b27002b4833014a37854fc6cd8e2eb286e