1.1.6 Ensure separate partition exists for /var

Information

The /var directory is used by daemons and other system services to temporarily store dynamic data. Some directories created by these processes may be world-writable.

Solution

For new installations, during installation create a custom partition setup and specify a separate partition for /var .
For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Unix

Control ID: a917efa85986f696c180dfd357a699c74de9c9b61822884784de2a85918c7e55