GEN001550 - All files and directories in user's home directories must be group-owned by a group the home directory's owner is a member.

Information

If a user's files are group-owned by a group where the user is not a member, unintended users may be able to access them.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Change the group of a file not group-owned by a group where the home directory's owner is a member.
# chgrp [user's primary group] [file with bad group ownership]

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22351, Rule-ID|SV-26453r1_rule, STIG-ID|GEN001550, Vuln-ID|V-22351

Plugin: Unix

Control ID: e0fb0acad754d7ca733d0bfde203b103b25cab86afeff18e18897d5ba01427dc