If the "autofs" status is set to "active" and is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
Fix
Configure the operating system to disable the ability to automount devices.
Turn off the automount service with the following commands: