5.1.2 Repair permissions regularly to ensure binaries and other System files have appropriate permissions

Information

Software installations, Upgrades and updates and end user activity can all end up changing the access controls on the Operating System. On a normal system lots of files get touched and changed and proper maintenance is necessary for good security. The standard software load on an end user system has so many moving parts that have regular updates to require periodic file permissions repair. We believe that a weekly permissions check should be scheduled to fix anything needed. Permission problems can lead to exploitable gaps in the operating system. Without expected controls in place the system is more likely to be successfully attacked.

Solution

Manually run the check using Disk Utility or through the command line. A schedule should be set in ls /etc/periodic/weekly/ diskutil repairPermissions / Impact: System executables and other important files could be modified much more easily if appropriate permissions are not in place.

See Also

https://workbench.cisecurity.org/files/299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: 4102cb623854f461f099d7a3fa80fb3ef7a6a6f97949357e84e27e936bc26602