Rule ID
SV-288292r1252461_rule
Version
V1R0.1
Removal of unneeded or nonsecure functions, ports, protocols, and services mitigate the risk of unauthorized connection of devices, unauthorized transfer of information, or other exploitation of these resources. The organization must perform a periodic scan/review of the application (as required by CCI-000384) and disable functions, ports, protocols, and services deemed to be unneeded or nonsecure.
Review the application documentation and deployed configuration to determine whether the application disables organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure. If the application does not disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure, this is a finding.
Configure the application to disable organization-defined functions, ports, protocols, and services (within the application) deemed unnecessary and/or nonsecure.