6.1.11 Ensure no unowned files or directories exist

Information

A new user who is assigned the deleted user's user ID or group ID may then end up 'owning' these files, and thus have more access on the system than was intended.

Solution

Locate files that are owned by users or groups not listed in the system configuration files, and reset the ownership of these files to some active user on the system as appropriate.

See Also

https://workbench.cisecurity.org/files/1859

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-16(3), CSCv6|14

Plugin: Unix

Control ID: 6be631d0d4f80baaebd5013e0ae4bdc725f966d5e8e9fac64c5f468a08aec6a8