# Cis GCP Cos 2.1.2

> Ensure X Window System is not installed

- Skill: `cyberstrikeus/cis-gcp-cos-2-1-2` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gcp-cos-2-1-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gcp-cos-2-1-2/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gcp-cos-2-1-2

---


# 2.1.2 Ensure X Window System is not installed (Automated)

## Description

The X Window System provides a Graphical User Interface (GUI) where users can have multiple windows in which to run programs and various add on. The X Windows system is typically used on workstations where users login, but not on servers where users typically do not login.

## Rationale

Unless your organization specifically requires graphical login access via X Windows, remove it to reduce the potential attack surface.

## Impact

Many Linux systems run applications which require a Java runtime. Some Linux Java packages have a dependency on specific X Windows xorg-x11-fonts. One workaround to avoid this dependency is to use the "headless" Java packages for your specific Java runtime, if provided by your distribution.

## Audit Procedure

Verify X Windows System is not installed. The following command should return empty result.

```bash
# grep xorg /etc/cos-package-info.json
```

## Expected Result

The command should return no output, confirming that X Window System packages are not installed.

## Remediation

An OS image update that does not include X Window System is required.

## CIS Controls

| Controls Version | Control                                                                                                                                                                                           | IG 1 | IG 2 | IG 3 |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---- | ---- | ---- |
| v8               | **2.3 Address Unauthorized Software** - Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently. | X    | X    | X    |
| v7               | **2.6 Address unapproved software** - Ensure that unauthorized software is either removed or the inventory is updated in a timely manner                                                          | X    | X    | X    |

## Profile

- Level 1 - Server

