Check: GEN003810
Title
The portmap or rpcbind service must not be running unless needed. (Cat II impact)
Discussion
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using remote procedure calls (RPCs).
Check Content
Check the status of the rpcbind service. # chkconfig If the service is online and is not documented as required, this is a finding.
Fix Text
Disable the portmap service.
Additional Identifiers
Rule ID:
Vulnerability ID: V-22429
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-001336 |
The organization retains individual training records for an organization-defined time period. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AT-4 |
Security Training Records |