Skip to content

Disable Booting from USB Devices in Boot Firmware

An XCCDF Rule

Description

Configure the system boot firmware (historically called BIOS on PC systems) to disallow booting from USB drives.

Rationale

Booting a system from a USB device would allow an attacker to circumvent any security measures provided by the operating system. Attackers could mount partitions and modify the configuration of the OS.

ID
xccdf_org.ssgproject.content_rule_bios_disable_usb_boot
Severity
Unknown
References
Updated