6.1.1 Audit system file permissions

Information

The RPM package manager has a number of useful options. One of these, the --verify (or -V ) option, can be used to verify that system packages are correctly installed. The --verify option can be used to verify a particular package or to verify all system packages. If no output is returned, the package is installed correctly. It is important to confirm that packaged system files and directories are maintained with the permissions they were intended to have from the OS vendor.

Solution

Correct any discrepancies found and rerun the audit until output is clean or risk is mitigated or accepted.

See Also

https://workbench.cisecurity.org/files/2171

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1)

Plugin: Unix

Control ID: e2726a2dd2c92fee0f12936bf39a0b1554cb99de0f3eff06fb86d4b149e02a4b