10.1 SN.1 Restrict access to suspend feature

Information

Solaris 11 does not enable the suspend capability by default and now uses the poweradm command to suspend the system.

Bear in mind that users with physical access to a system can simply remove power from the machine if they are truly motivated to take the system off-line, and granting the capability to use poweradm may be a more graceful way of allowing desktop users to shut down their own machines.

Solution

Perform the following to implement the recommended state:
# poweradm set suspend-enable=false
# poweradm update

See Also

https://workbench.cisecurity.org/files/612

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Unix

Control ID: 5cf81b742ebc3fbf461cf4e2e3f8761c2f52870a05e954247f7a5894d616ef18