AOSX-14-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another users files - User directory permissions

Information

Configuring the operating system to use the most restrictive permissions possible for user home directories helps to protect against inadvertent disclosures.

Solution

To ensure the appropriate permissions are set for each user on the system, run the following command:

diskutil resetUserPermissions / userid, where userid is the user name for the user whose home directory permissions need to be repaired.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_OS_X_10-14_V2R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-209610r610285_rule, STIG-ID|AOSX-14-002068, STIG-Legacy|SV-105093, STIG-Legacy|V-95955, Vuln-ID|V-209610

Plugin: Unix

Control ID: 26c9b605a5e9879b5be6b4a9135eef0262e70989f35de92e8fa82d2b55fdc796