3.3.3 Set umask Value in the Db2 Instance Owner's .profile

Information

The Db2 instance owner's .profile file in Linux sets the environment variables and the settings for the user. This file is specific to the Korn shell and BASH shell, and other shells may have a different file.

Rationale:

The umask value should be set to 022 for the owner of the Db2 software at all times to ensure files are not created with unnecessary privileges.

Solution

Add umask 022 to the .profile file.

See Also

https://workbench.cisecurity.org/benchmarks/10752

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 23c2ecf79d19536b1eaf3ed06035b5b5f47ae048bfed2c7b58d671aa9fe24fa3