9.24 Find Un-owned Files and Directories

Information

Sometimes when administrators delete users from the password file they neglect to remove all files owned by those users from the system.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Locate files that are owned by users or groups not listed in the system configuration files, and reset the ownership of these files to some active user on the system as appropriate. Note that the Solaris OS distribution is shipped with all files appropriately owned.

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-16(3)

Plugin: Unix

Control ID: 414b7559831fddf957ffc70f19b839519052d6d7e2f54dd2a9de47a78c2c304c