GEN008500 - The system must have IEEE 1394 (Firewire) disabled unless needed.

Information

Firewire is a common computer peripheral interface. Firewire devices may include storage devices that could be used to install malicious software on a system or exfiltrate data.

Solution

Disable the firewire module.

# echo 'exclude: s1394' >> /etc/system

Reboot for the changes to take effect.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-227979r603266_rule, STIG-ID|GEN008500, STIG-Legacy|SV-26972, STIG-Legacy|V-22580, Vuln-ID|V-227979

Plugin: Unix

Control ID: ab5aaed9760c52c3db7a82ccaf390835e2c43b072b1527716e9bc010151a4a62