GEN003050 - Crontab files must be group-owned by system, cron, or the crontab creator's primary group.

Information

To protect the integrity of scheduled system jobs and prevent malicious modification to these jobs, crontab files must be secured.

Solution

Change the group owner of the crontab file to system, cron, or the crontab's primary group.
Procedure:
# chgrp cron [crontab file]

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-39866r1_rule, STIG-ID|GEN003050, Vuln-ID|V-22385

Plugin: Unix

Control ID: 0d46fd3aae3a2c772fe8a9f2352a3af3791bdc97e12110088f997b6df5dde158