STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 6 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide

V-282755

CAT II (Medium)

TOSS 5 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.

Rule ID

SV-282755r1201616_rule

STIG

Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

Setting the most restrictive default permissions ensures that when new accounts are created, they do not have unnecessary access.

Check Content

Note: If the value of the "UMASK" parameter is set to "000" in "/etc/login.defs" file, the severity is raised to a CAT I.

Verify TOSS 5 defines default permissions for all authenticated users in such a way that the user can only read and modify their own files using the following command:

# grep -i umask /etc/login.defs

UMASK 077

If the value for the "UMASK" parameter is not "077", or the "UMASK" parameter is missing or is commented out, this is a finding.

Fix Text

Configure TOSS 5 to define default permissions for all authenticated users in such a way that the user can only read and modify their own files.

Add or edit the lines for the "UMASK" parameter in the "/etc/login.defs" file to "077":

UMASK 077