GEN008460 - The system must have USB disabled unless needed - '/proc/bus/usb'

Information

USB is a common computer peripheral interface. USB devices may include storage devices with the potential to install malicious software on a system or exfiltrate data.

Solution

Edit the grub bootloader file '/boot/grub/grub.conf' or '/boot/grub/menu.lst' by appending the 'nousb' parameter to the kernel boot line.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCE|CCE-4173-1, CCI|CCI-000366, Group-ID|V-22578, Rule-ID|SV-37981r1_rule, STIG-ID|GEN008460, Vuln-ID|V-22578

Plugin: Unix

Control ID: 420bfb16702b9229632038742f6af71dc83b5d8be4ed85227a6a8263d4aeeae7