Skip to content

The graphical display manager must not be installed on TOSS unless approved.

An XCCDF Rule

Description

Internet services that are not required for system or application processes must not be active to decrease the attack surface of the system. Graphical display managers have a long history of security vulnerabilities and must not be used, unless approved and documented.

ID
SV-253103r991589_rule
Version
TOSS-04-040610
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Document the requirement for a graphical user interface with the ISSO or reinstall the operating system without the graphical user interface. If reinstallation is not feasible, then continue with the following procedure:

Open an SSH session and enter the following commands:

$ sudo systemctl set-default multi-user.target