2.5 Create Separate Partition for /var

Information

The /var directory is used by daemons and other system services to temporarily store
dynamic data. Some directories created by these processes may be world-writable.

*Rationale*

Since the /var directory may contain world-writable files and directories, there is a risk of
resource exhaustion if it is not bound to a separate partition.

Solution

For new installations, during installation create a custom partition setup and specify a
separate partition for /var.For systems that were previously installed, use the Logical Volume Manager (LVM) to
create partitions.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1, CSCv7|5.1

Plugin: Unix

Control ID: 8de3530ad3c23e5bf960833d837f97b442bf1f95b38b9504c4f4f2405fffe22f