2.4.3.1 Ensure access to systemd timer unit files is configured

Information

For each timer file, a matching unit file must exist, describing the unit to activate when the timer elapses. By default, a service by the same name as the timer (except for the suffix) is activated. Example: a timer file foo.timer activates a matching service foo.service.

Timer units define scheduled execution and should be protected from unauthorized access to prevent persistence or malicious code execution.

Solution

Run the following commands to set permissions to mode 0644, owned by the root user, and owned by the root group:

# chmod u-x,go-wx
# chown root:root </path/to/systemd.timer>

Impact:

Service execution failures due to restrictive permissions and reduced functionality from least-privilege enforcement.

See Also

https://workbench.cisecurity.org/benchmarks/26236

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: c7abeca1d22f50425436b56ad3a51ef83ed333a49431c7c3bf298b7d1b607f66