Information
Administrators may delete users or groups from the system and neglect to remove all files and/or directories owned by those users or groups.
A new user or group who is assigned a deleted user's user ID or group ID may then end up "owning" a deleted user or group's files, and thus have more access on the system than was intended.
Solution
Remove or set ownership and group ownership of these files and/or directories to an active user on the system as appropriate.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION
References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-6b., 800-53|MP-2, CSCv7|14.6, Rule-ID|SV-230326r627750_rule, Rule-ID|SV-230327r627750_rule, Vuln-ID|V-230326, Vuln-ID|V-230327
Control ID: 552bd171e5962bac711f04ce7b868bbb63588a36bbbc1b83d00a015874b854af