10.1 SN.1 Restrict access to suspend feature

Information

Solaris 11 does not enable the suspend capability by default and now uses the poweradm command to suspend the system.
Bear in mind that users with physical access to a system can simply remove power from the machine if they are truly motivated to take the system off-line, and granting the capability to use poweradm may be a more graceful way of allowing desktop users to shut down their own machines.

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Unix

Control ID: f3ebc7264df53dd31f8917867cb7f0ecde86474933dfe6f92052210ff0215502