6.2.22 Ensure users' files and directories within the home directory permissions are 750 or more restrictive

Information

The operating system must be configured so that all files and directories contained in local interactive user home directories have a mode of 0750 or less permissive.

Rationale:

If a local interactive user files have excessive permissions, unintended users may be able to access or modify them.

Solution

Set the mode on files and directories in the local interactive user home directory with the following command:
Note: The example will be for the user smithj, who has a home directory of /home/smithj and is a member of the users group.

# chmod 0750 /home/smithj/<file>

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCI|CCI-000366, CSCv6|3.1, CSCv7|14.6, Rule-ID|SV-204473r603261_rule, STIG-ID|RHEL-07-020680

Plugin: Unix

Control ID: f83934c8ba9ae7ccea7855fea9d071985c1a2c6a73375340c2a5d82898a859d2