GEN008820 - The system package management tool must not automatically obtain updates

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

System package management tools can obtain a list of updates and patches from a package repository and make this information available to the SA for review and action. Using a package repository outside of the organization's control presents a risk that malicious packages could be introduced.

Solution

Configure the system package management tool to not automatically obtain updates.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

References: CAT|III, CCI|CCI-001233, Rule-ID|SV-38405r1_rule, STIG-ID|GEN008820, Vuln-ID|V-22589

Plugin: Unix

Control ID: 5d904b3971c7364becf7fb2b1b31a52880b2d9deccbe96a7bd29e264931d38aa