Rule ID
SV-258856r933629_rule
Version
V1R1
CCIs
CCI-000366
Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary access.
At the command line, run the following command to verify the default umask configuration: # grep '^UMASK' /etc/login.defs Expected result: UMASK 077 If the "UMASK" option is not set to "077", is missing or commented out, this is a finding.
Navigate to and open: /etc/login.defs Add or update the following line: UMASK 077