6.2.20 Ensure that all files and directories contained in local interactive user home directories are owned by the user

Information

The operating system must be configured so that all files and directories contained in local interactive user home directories are owned by the user of the home directory.

Rationale:

If local interactive users do not own the files in their directories, unauthorized users may be able to access them. Additionally, if files are not owned by the user, this could be an indication of system compromise.

Solution

Change the owner of a local interactive user's files and directories to that owner. To change the owner of a local interactive user's files and directories, use the following command:
Note: The example will be for the user smithj, who has a home directory of /home/smithj.

# chown smithj /home/smithj/<file or directory>

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCI|CCI-000366, CSCv6|3.1, CSCv7|14.6, Rule-ID|SV-204471r744105_rule, STIG-ID|RHEL-07-020660

Plugin: Unix

Control ID: f978722dd73a9a6edcbbbcdc0435ee57fbcdd78defd0d96b4f026a5aabeb15f6