SV-280962r1195350_rule
V-280962
SRG-OS-000378-GPOS-00163
RHEL-10-200560
CAT II
10
Configure RHEL 10 to have the USBGuard package installed with the following command:
$ sudo dnf -y install usbguard
Enable the service to start on boot and then start it with the following commands:
$ sudo systemctl enable usbguard
$ sudo systemctl start usbguard
Verify the status of the service with the following command:
$ sudo systemctl status usbguard
Note: USBGuard must be configured to allow authorized devices once it is enabled on RHEL 10.
Verify RHEL 10 has USBGuard installed on the operating system with the following command:
$ sudo dnf list --installed usbguard
Installed Packages
usbguard.x86_64 1.1.3-6.el10 @rhel-10-for-x86_64-appstream-rpms
If the USBGuard package is not installed, ask the SA to indicate how unauthorized peripherals are being blocked.
If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.
If the system is a virtual machine with no virtual or physical USB peripherals attached, this is not a finding.
V-280962
False
RHEL-10-200560
Verify RHEL 10 has USBGuard installed on the operating system with the following command:
$ sudo dnf list --installed usbguard
Installed Packages
usbguard.x86_64 1.1.3-6.el10 @rhel-10-for-x86_64-appstream-rpms
If the USBGuard package is not installed, ask the SA to indicate how unauthorized peripherals are being blocked.
If there is no evidence that unauthorized peripherals are being blocked before establishing a connection, this is a finding.
If the system is a virtual machine with no virtual or physical USB peripherals attached, this is not a finding.
M
5733