Details
To centralize the management of privileged account crontabs, of the default system accounts, only root may have a crontab.
Solution
Remove default system accounts (such as bin, sys, adm, or lpd) from the ‘cron.allow’ file, or add those accounts to the ‘cron.deny’ file.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Unix.
References
- 800-53|CM-6b.
- CAT|II
- CCI|CCI-000366
- Rule-ID|SV-215192r508663_rule
- STIG-ID|AIX7-00-001033
- STIG-Legacy|SV-101707
- STIG-Legacy|V-91609
- Vuln-ID|V-215192