1.1.5 Create Separate Partition for /var

Information

The /var directory is used by daemons and other system services to temporarily store dynamic data. Some directories created by these processes may be world-writable.

Rationale:

Since the /var directory may contain world-writable files and directories, there is a risk of resource exhaustion if it is not bound to a separate partition.

Solution

For new installations, check the box to 'Review and modify partitioning' and create a separate partition for /var.
For systems that were previously installed, use the Logical Volume Manager (LVM) to create partitions.

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6, 800-53|SC-7(10), CSCv6|3.1, CSCv7|5.1, CSCv7|13

Plugin: Unix

Control ID: 10067ea4851713779b8a3620e4976c5ae367a0a764b34e3e7b33b871d10ba4a7