9.5 Verify that no UID 0 accounts exist other than root

Information

Any account with UID 0 has superuser privileges on the system.

Solution

Delete any other entries that are displayed.

Finer granularity access control for administrative access can be obtained by using Oracle's Role-Based Access Control (RBAC) system.

RBAC configurations can be monitored via the /etc/user_attr file to make sure that privileges are managed appropriately.

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(5), CSCv6|5.1

Plugin: Unix

Control ID: 7146a2f8b3e1ed6e74b344dca5390093af508a35b2710e2bb096fafe6ecc0232