9.16 Check for Duplicate GIDs

Information

Although the groupadd program will not let you create a duplicate Group ID (GID), it is
possible for an administrator to manually modify group(4) and change the GID field.

User groups must be assigned unique GIDs for accountability and to ensure appropriate
access protections.

Solution

Correct or justify any items discovered in the Audit step. Determine if there exists any
duplicate group identifiers, and work with each respective group owner to remediate this
issue and ensure that the group ownership of their files are set to an appropriate value.

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-4d.

Plugin: Unix

Control ID: 58d8b134420fc81dce41024468be5d059b2a4b5a97a2fa6efa649c138cbd01cf