1.1.6 Ensure separate partition exists for /var

Information

Since the /var directory may contain world-writable files and directories, there is a risk of resource exhaustion if it is not bound to a separate partition.

Solution

For new installations, during installation create a custom partition setup and specify a separate partition for /var.For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: c65b9c30a4e98073f2cb8cd70e83281bf095e3f3dab3fb78ccebca23d10a43d2