OSX00185 - Change Global umask

Information

The default umask setting of 022 (in octal) removes group and other write permissions. Group members and other users can read and run these files or folders. Changing the umask setting to 027 enables group members to read files and folders and prevents others from accessing the files and folders.

Solution

1. Open a terminal session and enter the following command- sudo echo 'umask 027' >> /etc/launchd.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, Rule-ID|SV-31351r1_rule, STIG-ID|OSX00185, Vuln-ID|V-25277

Plugin: Unix

Control ID: e9389642cf5b0585f9c5c86000447aea9f57b8677debc464419dc38d651aa6ba