5.1.3 Check System folder for world writable files

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Folders in /System should not be world writable. The audit check excludes the 'Drop Box' folder that is part of Apple's default user template.

Solution

Change permissions so that 'Others' can only execute. (Example Below)
sudo chmod -R o-w /Bad/Directory

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 0b34ef30c520272745dc348c91f30f292e2184506e56a4489b3853eee508602c