GEN000520 - The root user must not own the logon session for an application requiring a continuous display.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If an application is providing a continuous display and is running with root privileges, unauthorized users could interrupt the process and gain root access to the system.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the system so the owner of a session requiring a continuous screen display, such as a network management display, is not root. Ensure the display is also located in a secure, controlled access area. Document and justify this requirement. Ensure the terminal and keyboard for the display (or workstation) are secure from all but authorized personnel by maintaining them in a secure area, in a locked cabinet where a swipe card, or other positive forms of identification, must be used to gain entry.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(8), CAT|II, CCI|CCI-002233, Rule-ID|SV-227580r603266_rule, STIG-ID|GEN000520, STIG-Legacy|SV-769, STIG-Legacy|V-769, Vuln-ID|V-227580

Plugin: Unix

Control ID: a7d3c564e06e2473029dca8b31369e1d8f2522d3dd4dbf2d8a765ca5cab2b70b