7.9 Lock Inactive User Accounts - Check if definact is set to 35.

Information

Guidelines published by the U.S. Department of Defense specify that user accounts must be locked out after 35 days of inactivity. This number may vary based on the particular site's policy.

Note - To set the default for creating user accounts to expire after 35 days of inactivity, use the command-
useradd -D -f 35

This will create or modify the file /usr/sadm/defadduser with an entry definact=35 (or whatever you set it to for your site's policy).

Solution

Please refer to the remediation steps on page 109 of the CIS document.

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(3), CSCv6|16.1, CSCv6|16.6

Plugin: Unix

Control ID: a5d69ed90416f74e3b49b5bac334215e450a3975f47ac1208d20c5322f6b1331