4.7.2.14 /var/ct/RMstart.log

Information

The /var/ct/RMstart.log is the logfile used by RMC and can contain sensitive data that must be secured.

Rationale:

RMC provides a single monitoring and management infrastructure for both RSCT peer domains and management domains. Its generalized framework is used by cluster management tools to monitor, query, modify, and control cluster resources, /var/ct/RMstart.log is the logfile used by RMC and can contain sensitive data that must be secured.

Solution

Remove world read and write from /var/ct/RMstart.log:

chmod o-rw /var/ct/RMstart.log

Default Value:

644

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: a27acb8a8d5e1cd43647f583562d997fbaa7ac549af09660d6281ef28271ff72