UCF STIG Viewer Logo

The root user must not own the logon session for an application requiring a continuous display.


Overview

Finding ID Version Rule ID IA Controls Severity
V-769 GEN000520 SV-769r7_rule PESL-1 Medium
Description
If an application is providing a continuous display and is running with root privileges, unauthorized users could interrupt the process and gain root access to the system.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-229r2_chk )
If there is an application running on the system that is continuously in use (such as a network monitoring application), ask the SA what the name of the application is. Execute ps –ef | more to determine which user owns the process(es) associated with the application. If the owner is root, this is a finding.
Fix Text (F-923r2_fix)
Configure the system so the owner of a session requiring a continuous screen display, such as a network management display, is not root. Ensure the display is also located in a secure, controlled access area. Document and justify this requirement. Ensure the terminal and keyboard for the display (or workstation) are secure from all but authorized personnel by maintaining them in a secure area, in a locked cabinet where a swipe card, or other positive forms of identification, must be used to gain entry.