Check: TOSS-04-020310
Tri-Lab Operating System Stack (TOSS) 4 STIG:
TOSS-04-020310
(in versions v2 r1 through v1 r1)
Title
All TOSS local interactive user home directories must be owned by root. (Cat II impact)
Discussion
Users' home directories/folders may contain information of a sensitive nature. Non-privileged users should coordinate any sharing of information with an SA through shared resources.
Check Content
Check that all user home directories are owned by the root user with the following command: $ find $(awk -F: '($3>=1000)&&($7 !~ /nologin/){print $6}' /etc/passwd) -maxdepth 0 -not -user root -ls If there is any output, this is a finding.
Fix Text
Change the owner of interactive user's home directories to root. To change the owner of a local interactive user's home directory, use the following command: Note: The example will be for the user "smithj." $ sudo chown root /home/smithj
Additional Identifiers
Rule ID: SV-252970r991592_rule
Vulnerability ID: V-252970
Group Title: SRG-OS-000480-GPOS-00230
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |