5.1.6 Ensure No World Writable Files Exist in the System Folder

Information

Software sometimes insists on being installed in the /System/Volumes/Data/System Directory and have inappropriate world-writable permissions.

Rationale:

Folders in /System/Volumes/Data/System should not be world-writable. The audit check excludes the 'Drop Box' folder that is part of Apple's default user template.

Solution

Run the following command to set permissions so that folders are not world-writable in the /System folder:

$ sudo /bin/chmod -R o-w /Path/<baddirectory>

example:

$ sudo /bin/chmod -R o-w /System/Library/baddir

See Also

https://workbench.cisecurity.org/files/3569

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 19d99d26f1d05286a65cc75b6be401bf038e949df38a94ed62433c12c03954b6