Information
If an application is providing a continuous display and is running with root privileges, unauthorized users could interrupt the process and gain root access to the system.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Configure the system so the owner of a session requires a continuous screen display, such as a network management display, is not root. Ensure the display is also located in a secure, controlled access area. Document and justify this requirement and ensure the terminal and keyboard for the display (or workstation) are secure from all but authorized personnel by maintaining them in a secure area, in a locked cabinet where a swipe card, or other positive forms of identification, must be used to gain entry.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT
References: 800-53|AC-6, 800-53|CM-5(6), CAT|II, CCI|CCI-000225, CCI|CCI-001499, Rule-ID|SV-218224r603259_rule, STIG-ID|GEN000520, STIG-Legacy|SV-63649, STIG-Legacy|V-769, Vuln-ID|V-218224
Control ID: ae99fcdedb3cbf5334ddb64f444ee267178a9bc13e913785bd8c7c8f1acac366