5.1.3 Check System folder for world writable files

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Software sometimes insists on being installed in the /System Directory and have inappropriate world writable permissions.

Rationale:

Folders in /System should not be world writable. The audit check excludes the 'Drop Box' folder that is part of Apple's default user template.

Solution

Change permissions so that 'Others' can only execute. (Example Below)

sudo chmod -R o-w /Bad/Directory

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: a50568fa5e5730fd507af4ecd223394d4affbe4ddfec197ff3636049cdced0f4