---
title: CIS Ubuntu 24.04 Services: 31 Checks | Wartiva
description: Wartiva's 31 checks for section 2, Services, of the CIS Ubuntu Linux 24.04 LTS Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html
updated: 2026-10-07
---

CIS Ubuntu Linux 24.04 LTS Benchmark · Section 2

# Ubuntu 24.04 Services: 31 Checks

Wartiva runs 31 checks for section 2, Services, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 2.1 Configure Server Services

### [Ensure autofs services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#autofs-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Autofs service is in use.

Checks that the autofs automounting service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Automounting lets anyone with physical access attach removable media and have its contents mounted without explicit permission, widening the attack surface.

**Impact:** Automatic mounting of configured removable media stops; media must be mounted manually.

#### Remediation

From the command line:

```sh
systemctl stop autofs.service
systemctl mask autofs.service
```

Framework mappings

- **CIS Controls v8**: 10.3 Disable Autorun and Autoplay for Removable Media
- **NIST SP 800-53 Rev. 5**: MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure avahi daemon services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#avahi-daemon-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Avahi daemon service is in use.

Checks that the avahi-daemon service and socket are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Avahi zeroconf service discovery is rarely needed and publishes/advertises services on the local network, expanding attack surface.

**Impact:** Automatic discovery of local network services and printers via mDNS/DNS-SD stops.

#### Remediation

From the command line:

```sh
systemctl stop avahi-daemon.socket avahi-daemon.service
systemctl mask avahi-daemon.socket avahi-daemon.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure dhcp server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#dhcp-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Dhcp server service is in use.

Checks that the kea DHCPv4/DHCPv6/DDNS server services are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** A rogue or misconfigured DHCP server can disrupt the network by handing out incorrect addresses, DNS servers, or gateways; unless the host is a DHCP server the kea services should not run.

**Impact:** The system can no longer serve DHCP leases.

#### Remediation

From the command line:

```sh
systemctl stop kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
systemctl mask kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure dns server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#dns-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Dns server service is in use.

Checks that the bind9 DNS server (named.service) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Unless the host is a designated DNS server, the bind9 package/service should not run so as to reduce attack surface.

**Impact:** The system can no longer serve DNS.

#### Remediation

From the command line:

```sh
systemctl stop named.service
systemctl mask named.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure dnsmasq services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#dnsmasq-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Dnsmasq service is in use.

Checks that the dnsmasq service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** dnsmasq provides DNS caching/forwarding and DHCP; unless required it should not run.

**Impact:** Local DNS caching/forwarding and DHCP via dnsmasq stop.

#### Remediation

From the command line:

```sh
systemctl stop dnsmasq.service
systemctl mask dnsmasq.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure ftp server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#ftp-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Ftp server service is in use.

Checks that the vsftpd FTP server service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** FTP transmits data and credentials in the clear; unless an FTP server is required, vsftpd should not run.

**Impact:** The system can no longer act as an FTP server.

#### Remediation

From the command line:

```sh
systemctl stop vsftpd.service
systemctl mask vsftpd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure ldap server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#ldap-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Ldap server service is in use.

Checks that the slapd OpenLDAP server service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Unless the host is an LDAP server, slapd should not run so as to reduce attack surface.

**Impact:** The system can no longer serve LDAP directory queries.

#### Remediation

From the command line:

```sh
systemctl stop slapd.service
systemctl mask slapd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure message access server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#message-access-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Message access server service is in use.

Checks that the dovecot IMAP/POP3 server service and socket are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Unless the host provides IMAP/POP3 mail access, the dovecot service should not run so as to reduce attack surface.

**Impact:** IMAP/POP3 message access served by dovecot stops.

#### Remediation

From the command line:

```sh
systemctl stop dovecot.socket dovecot.service
systemctl mask dovecot.socket dovecot.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure network file system services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#network-file-system-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Network file system service is in use.

Checks that the NFS server service (nfs-server.service) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** If the host does not export NFS shares, the nfs-kernel-server service should not run so as to reduce the remote attack surface.

**Impact:** The system can no longer export NFS shares.

#### Remediation

From the command line:

```sh
systemctl stop nfs-server.service
systemctl mask nfs-server.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure nis server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#nis-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Nis server service is in use.

Checks that the ypserv NIS server service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** NIS is inherently insecure (weak authentication, DoS and buffer-overflow history) and has been superseded by LDAP; ypserv should not run.

**Impact:** The system can no longer serve NIS maps.

#### Remediation

From the command line:

```sh
systemctl stop ypserv.service
systemctl mask ypserv.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure print server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#print-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Print server service is in use.

Checks that the CUPS print service and socket are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** CUPS accepts local and remote print jobs and offers web-based admin; unless printing is needed it should not run.

**Impact:** Printing (including accepting remote print jobs) stops.

#### Remediation

From the command line:

```sh
systemctl stop cups.socket cups.service
systemctl mask cups.socket cups.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure rpcbind services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#rpcbind-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Rpcbind service is in use.

Checks that the rpcbind (portmapper) service and socket are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** The portmapper is a UDP amplification vector suited to DDoS attacks; unless RPC services are required, rpcbind should not run.

**Impact:** RPC-based services (e.g. NFS) that depend on rpcbind will not function.

#### Remediation

From the command line:

```sh
systemctl stop rpcbind.socket rpcbind.service
systemctl mask rpcbind.socket rpcbind.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure rsync services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#rsync-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Rsync service is in use.

Checks that the rsync daemon service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** The rsync protocol is unencrypted; the rsync daemon should not run so as to reduce attack surface.

**Impact:** Serving files via the rsync daemon stops (rsync-over-ssh is unaffected).

#### Remediation

From the command line:

```sh
systemctl stop rsync.service
systemctl mask rsync.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure samba file server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#samba-file-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Samba file server service is in use.

Checks that the Samba file server service (smbd.service) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Unless SMB file/directory sharing to Windows clients is needed, smbd should not run so as to reduce attack surface.

**Impact:** SMB file/print sharing stops.

#### Remediation

From the command line:

```sh
systemctl stop smbd.service
systemctl mask smbd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure snmp services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#snmp-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Snmp service is in use.

Checks that the SNMP server service (snmpd.service) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** SNMPv1/v2 transmit community strings and data in the clear; unless SNMP is required (and hardened to v3), snmpd should not run.

**Impact:** SNMP monitoring of the host stops.

#### Remediation

From the command line:

```sh
systemctl stop snmpd.service
systemctl mask snmpd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure telnet server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#telnet-server-services-are-not-in-use)

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Telnet server service is in use.

Checks that the telnet server service (inetutils-inetd.service serving telnetd) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Telnet is unencrypted; anyone able to sniff traffic can capture credentials. The telnet server should not run.

**Impact:** Inbound telnet logins stop; use SSH instead.

#### Remediation

From the command line:

```sh
systemctl stop inetutils-inetd.service
systemctl mask inetutils-inetd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure tftp server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#tftp-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Tftp server service is in use.

Checks that the TFTP server service (tftpd-hpa.service) is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** TFTP has no encryption, access control, or authentication; unless required (e.g. PXE boot) the TFTP server should not run.

**Impact:** TFTP file serving (including network boot support) stops.

#### Remediation

From the command line:

```sh
systemctl stop tftpd-hpa.service
systemctl mask tftpd-hpa.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure web proxy server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#web-proxy-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Web proxy server service is in use.

Checks that the Squid web proxy service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Unless the host is a designated proxy server, the squid service should not run so as to reduce attack surface.

**Impact:** Web proxying via squid stops.

#### Remediation

From the command line:

```sh
systemctl stop squid.service
systemctl mask squid.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure web server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#web-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Web server service is in use.

Checks that the apache2 and nginx web server services/sockets are masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** Web servers add listening network services that process untrusted remote input and expose extra attack surface via modules; they should not run unless hosting web content.

**Impact:** The host can no longer serve web content from apache2 or nginx.

#### Remediation

From the command line:

```sh
systemctl stop apache2.socket apache2.service
systemctl mask apache2.socket apache2.service
systemctl stop nginx.service
systemctl mask nginx.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure X window server services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#x-window-server-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** X window server package is installed.

Checks that the X Window System server package (xserver-common) is not installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** Servers typically do not need a graphical X session; removing the X server reduces attack surface.

**Impact:** Graphical X sessions become unavailable; a GDM in use may depend on this package and should be reviewed first.

#### Remediation

From the command line:

```sh
apt purge xserver-common
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure xinetd services are not in use](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#xinetd-services-are-not-in-use)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

**Finding:** Xinetd service is in use.

Checks that the xinetd super-daemon service is masked or stopped.

This rule fails when the service unit is `loaded` (not masked) and `RUNNING`.

**Rationale:** xinetd launches on-demand network daemons; unless xinetd services are required it should not run so as to reduce attack surface.

**Impact:** Any services launched via xinetd will no longer start on demand.

#### Remediation

From the command line:

```sh
systemctl stop xinetd.service
systemctl mask xinetd.service
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.2 Configure Client Services

### [Ensure ftp client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#ftp-client-is-not-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Ftp client package is installed.

Checks that neither the ftp nor tnftp client package is installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** FTP is a cleartext protocol; unless required, the FTP client should be removed to reduce attack surface.

**Impact:** The ftp/tnftp client commands become unavailable; use SFTP instead.

#### Remediation

From the command line:

```sh
apt purge ftp
apt purge tnftp
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure ldap client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#ldap-client-is-not-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Ldap client package is installed.

Checks that the ldap-utils client package is not installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** If the host does not need to act as an LDAP client, removing ldap-utils reduces attack surface.

**Impact:** LDAP client utilities become unavailable, which may inhibit LDAP-based authentication.

#### Remediation

From the command line:

```sh
apt purge ldap-utils
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure nis client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#nis-client-is-not-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Nis client package is installed.

Checks that the nis client package is not installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** NIS is insecure (weak authentication, DoS/buffer-overflow history) and superseded by LDAP; the client should be removed to prevent misuse.

**Impact:** NIS client lookups become unavailable.

#### Remediation

From the command line:

```sh
apt purge nis
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure rsh client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#rsh-client-is-not-installed)

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Rsh client package is installed.

Checks that the rsh-client package (rsh, rcp, rlogin) is not installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** The rsh family sends credentials in the clear and has numerous exposures; removing the client prevents users from inadvertently exposing credentials.

**Impact:** The rsh, rcp, and rlogin commands become unavailable; use SSH/SCP instead.

#### Remediation

From the command line:

```sh
apt purge rsh-client
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure talk client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#talk-client-is-not-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Talk client package is installed.

Checks that the talk client package is not installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** talk uses unencrypted protocols and presents a security risk; the client should be removed unless required.

**Impact:** The talk messaging command becomes unavailable.

#### Remediation

From the command line:

```sh
apt purge talk
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure telnet client is not installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#telnet-client-is-not-installed)

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

**Finding:** Telnet client package is installed.

Checks that neither the telnet nor inetutils-telnet client package is installed.

This rule fails when the installed package `name` is one of the prohibited packages.

**Rationale:** The telnet protocol is unencrypted; the client should be removed so credentials cannot be exposed over telnet. Use SSH instead.

**Impact:** The telnet client command becomes unavailable.

#### Remediation

From the command line:

```sh
apt purge telnet inetutils-telnet
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 2.3 Configure Time Synchronization

### [Ensure systemd-timesyncd is enabled and running](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#systemd-timesyncd-is-enabled-and-running)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.2

**Finding:** systemd-timesyncd is not enabled and running.

Checks that systemd-timesyncd.service is enabled and active, treating a masked unit (chrony chosen instead) as compliant.

This rule fails when the time-sync service is neither masked nor enabled-and-running.

**Rationale:** Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.

**Impact:** None; enables the system time synchronization client.

#### Remediation

From the command line:

```sh
systemctl unmask systemd-timesyncd.service
systemctl --now enable systemd-timesyncd.service
```

Framework mappings

- **CIS Controls v8**: 8.4 Standardize Time Synchronization
- **NIST SP 800-53 Rev. 5**: AU-8 Time Stamps; AU-12 Audit Record Generation
- **NIST SP 800-171 Rev. 2**: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **CMMC 2.0 Level 2**: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **PCI DSS v4.0.1**: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure chrony is enabled and running](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#chrony-is-enabled-and-running)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.3

**Finding:** Chrony is not enabled and running.

Checks that chrony.service is enabled and active, treating a masked unit (systemd-timesyncd chosen instead) as compliant.

This rule fails when the time-sync service is neither masked nor enabled-and-running.

**Rationale:** Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.

**Impact:** None; enables the chrony time synchronization daemon.

#### Remediation

From the command line:

```sh
systemctl unmask chrony.service
systemctl --now enable chrony.service
```

Framework mappings

- **CIS Controls v8**: 8.4 Standardize Time Synchronization
- **NIST SP 800-53 Rev. 5**: AU-8 Time Stamps; AU-12 Audit Record Generation
- **NIST SP 800-171 Rev. 2**: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **CMMC 2.0 Level 2**: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **PCI DSS v4.0.1**: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure chrony is running as user _chrony](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#chrony-is-running-as-user-chrony)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.3

**Finding:** Chrony is not running as user _chrony.

Checks that the chrony time daemon runs under the dedicated _chrony account rather than root, using the service unit userName field.

This rule fails when `chrony.service` runs as a user other than `_chrony`.

**Rationale:** Running chronyd with only the required privileges limits the impact of a compromise of the time daemon.

**Impact:** None; chronyd continues to function under its dedicated account.

#### Remediation

From the command line:

```sh
# add or edit in /etc/chrony/chrony.conf (or a .conf drop-in under /etc/chrony/conf.d/):
# user _chrony
systemctl restart chrony.service
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## 2.4 Job Schedulers

### [Ensure cron daemon is enabled and active](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/services.html#cron-daemon-is-enabled-and-active)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.4.1

**Finding:** Cron daemon is not enabled and active.

Checks that the cron daemon (cron.service) is enabled and active so scheduled system and security maintenance jobs run.

This rule fails when `cron.service` is masked, disabled, or not `RUNNING`.

**Rationale:** Cron runs scheduled maintenance and security-monitoring jobs; if the daemon is not enabled and running those jobs will not execute.

**Impact:** None; ensures scheduled jobs continue to run.

#### Remediation

From the command line:

```sh
systemctl unmask cron.service
systemctl --now enable cron.service
```

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
