3.7.2.11 /var/adm/cron/cron.allow

Information

The /var/adm/cron/cron.allow file contains a list of users who can schedule jobs via the cron command.

Rationale:

The /var/adm/cron/cron.allow file controls which users can schedule jobs via cron. Only the root user should have permissions to create, edit, or delete this file.

Solution

Apply the appropriate permissions to /var/adm/cron/cron.allow:

chown root:sys /var/adm/cron/cron.allow
chmod u=r,go= /var/adm/cron/cron.allow

Default Value:

N/A

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 7e2239e439b1e28e53d8703dab20f020424a24836533d168e8c9b81330db8584