5.1.2 Repair permissions regularly to ensure binaries and other System files have appropriate permissions

Information

Permission problems can lead to exploitable gaps in the operating system. Without expected controls in place the system is more likely to be successfully attacked.

Solution

Check the System logs to ensure that Repair permissions was run in the last week:
cat /var/log/system.log* | grep RepairPermissions
Manually run the check using Disk Utility or through the command line. A schedule should be set in ls /etc/periodic/weekly/
/usr/sbin/diskutil repairPermissions /

See Also

https://workbench.cisecurity.org/files/300

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Unix

Control ID: eb00239618e1c47eecc12633ffe8007372724b438cc39891b7f39c33953af281