GEN008480 - The system must have USB Mass Storage disabled unless needed.

Information

USB is a common computer peripheral interface. USB devices may include storage devices with the potential to install malicious software on a system or exfiltrate data

Solution

Prevent the usb-storage module from loading.
# echo 'install usb-storage /bin/true' >> /etc/modprobe.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-22579, Rule-ID|SV-37982r1_rule, STIG-ID|GEN008480, Vuln-ID|V-22579

Plugin: Unix

Control ID: 59aa2d3bae3a9f39992081c8a1986ccace2858135f66bdc8a9b774a85ab30161