1.1.6 Ensure separate partition exists for /var

Information

Since the /var directory may contain world-writable files and directories, there is a risk of resource exhaustion if it is not bound to a separate partition.

Solution

For new installations, during installation create a custom partition setup and specify a separate partition for /var.For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Amazon_Linux_Benchmark_v2.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: e5394c8c43933f7064e68e6d20a5450f3246753750f5d15134e54d521424fb5d