1.4 Set permissions on local-settings.js

Information

Set permissions on local-settings.js so that it can only be modified or deleted by an Administrator.

Rationale:

Any users with the ability to modify the local-settings.js file can bypass all security configurations by changing the file or deleting it.

Impact:

Non-administrative users will not be able to write to the local-settings.js.

Solution

Deny non-administrators the ability to write to local-settings.js.

Default Value:

Not configured.

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(6)

Plugin: Unix

Control ID: 5f0f4dd9a50754b213be6214e4e36621096ae92825301240ce4d7714b4053641