5.1.1 Secure Home Folders

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Allowing all users to view the top level of all networked user's home folder may not be desirable since it may lead to the revelation of sensitive information.

Solution

Perform the following to implement the prescribed state:
Run one of the following commands in Terminal:
sudo chmod -R og-rwx /Users/<username>
sudo chmod -R og-rw /Users/<username>
Substitute user name in <username>
This command has to be run for each user account with a local home folder.

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.9_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: 5243e2f1fa9dd14d286333a05bcbf19fa3a3b03c731d1e14f8ab8dab1f047d32