7.3 Set Default Group for root Account

Information

The usermod command can be used to specify which group the root user belongs to. This affects permissions of files that are created by the root user.

Rationale:

Using GID 0 for the _root_ account helps prevent root-owned files from accidentally becoming accessible to non-privileged users.

Solution

Run the following command to assign gid 0 to root:

# usermod -g 0 root

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|5.1, CSCv7|5.1

Plugin: Unix

Control ID: 0472912ac547987ca5cd34e859509f91a3e07f4d8a00d5af6b43dd8ee899089c