5.068 - Unnecessary services are not disabled.

Information

Unnecessary Services increase the attack surface of a system. Some Services may be run under the local System Account, which generally has more permissions than required by the service. Compromising a service could allow an intruder to obtain System permissions and open the system to a variety of attacks.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the system to disable any services that are not required.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_DC_V6R47_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, CSCv6|9.1, Rule-ID|SV-16965r1_rule, STIG-ID|5.068, Vuln-ID|V-3487

Plugin: Windows

Control ID: 3ee369be8593eb42d4897bd13910c29da6ac64e3c24917d2192926c5eee1fb7d