4.7.1.6 /var/adm/ras

Information

The /var/adm/ras directory contains log files which contain sensitive information such as login times and IP addresses.

Rationale:

The log files in the /var/adm/ras directory can contain sensitive information such as login times and IP addresses, which may be altered by an attacker when removing traces of system access. All files in this directory must be secured from unauthorized access and modifications.

Solution

Remove world read and write access from all files in /var/adm/ras:

chmod o-rw /var/adm/ras/*

Default Value:

N/A

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: b818491cf5ac75238772d2452f49d97af11647cebae3aaa06a7ba12846063d35