3.7.2.4 /etc/group

Information

The /etc/group file contains a list of the groups defined within the system.

Rationale:

The /etc/group file defines basic group attributes. Since the file contains sensitive information, it must be properly secured.

Solution

Ensure correct ownership and permissions are in place for /etc/group:

chown root:security /etc/group
chmod u=rw,go=r /etc/group

Default Value:

644

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: a84915b6e3c3cbcff41c2167da2435756056b83e0bb0daeeff06dacdc0ed0b96