6.2 Ensure Log Files Are Stored on a Non-System Partition

Information

MySQL log files can be set in the MySQL configuration to exist anywhere on the filesystem. It is common practice to ensure that the system filesystem is left uncluttered by application logs. System filesystems include the root (/), /var, or /usr.

Rationale:

Moving the MySQL logs off the system partition will reduce the probability of denial of service via the exhaustion of available disk space to the operating system.

Solution

Perform the following actions to remediate this setting:

Open the MySQL configuration file (my.cnf)

Locate the log-bin entry and set it to a file not on root (/), /var, or /usr

See Also

https://workbench.cisecurity.org/files/3844

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv7|6.4

Plugin: MySQLDB

Control ID: e5737e13600ab1cd5e58f2f9d969ac2845817b61952680d93b32ae7382c838f3