3.7.2.10 /var/adm/cron/at.allow

Information

The /var/adm/cron/at.allow file contains a list of users who can schedule jobs via the at command.

Rationale:

The /var/adm/cron/at.allow file controls which users can schedule jobs via the at command. Only the root user should have permissions to create, edit, or delete this file.

Solution

Apply the appropriate permissions to /var/adm/cron/at.allow:

chown root:sys /var/adm/cron/at.allow
chmod u=r,go= /var/adm/cron/at.allow

Default Value:

N/A

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: af3b11264efa65986b39daaec327cb1db45051bfe6e87e9d7cc8dbe370c9c897