Rule ID
SV-215198r991592_rule
Version
V3R2
CCIs
Users' home directories/folders may contain information of a sensitive nature. Non-privileged users should coordinate any sharing of information with an SA through shared resources.
Check the mode of the root home directory by running the following commands:
# ls -ld `grep "^root" /etc/passwd | awk -F":" '{print $6}'`
The above command should yield the following output:
drwx------ 22 root system 4096 Sep 06 18:00 /root
If the mode of the directory is not equal to "0700", this is a finding.Use the following command to change protections for the root home directory: # chmod 0700 /root.