5.1.4 Check System folder for world writable files

Information

Folders in /System should not be world writable. The audit check excludes the 'Drop Box' folder that is part of Apple's default user template.

Solution

Change permissions so that 'Others' can only execute. (Example Below)
sudo chmod -R o-w /Bad/Directory

See Also

https://workbench.cisecurity.org/files/300

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 7af7b0df0a2214a66ca67904af40ae6e7193863fb40d496244a3341392f3b92b