GEN008460 - The system must have USB disabled unless needed - 'lslpp'

Information

USB is a common computer peripheral interface. USB devices may include storage devices that could be used to install malicious software on a system or exfiltrate data.

Solution

Disable USB devices on the system. Use SMIT to remove the following filesets.

devices.usbif.*

# smitty remove

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-22578, Rule-ID|SV-38833r1_rule, STIG-ID|GEN008460, Vuln-ID|V-22578

Plugin: Unix

Control ID: e953b44a09fd46402e020844f2ed9ccc446d8d2d65e7256b8ce8a7bc54baa92c