# Cis GCP Cos 1.1.9

> Ensure nodev option set on /home partition

- Skill: `cyberstrikeus/cis-gcp-cos-1-1-9` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gcp-cos-1-1-9`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gcp-cos-1-1-9/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gcp-cos-1-1-9

---


# 1.1.9 Ensure nodev option set on /home partition (Automated)

## Description

The `nodev` mount option specifies that the filesystem cannot contain special devices.

## Rationale

Since the user partitions are not intended to support devices, set this option to ensure that users cannot attempt to create block or character special devices.

## Audit Procedure

Verify that the `nodev` option is set if a `/home` partition exists.
Run the following command and verify that nothing is returned:

```bash
# mount | grep -E '\s/home\s' | grep -v nodev
```

## Expected Result

The command should return no output, confirming that the `nodev` option is set on the `/home` partition.

## Remediation

Run the following command to remount /home:

```bash
# mount -o remount,nodev /home
```

**Note:** `/etc` is stateless on Container-Optimized OS. Therefore, `/etc` cannot be used to make these changes persistent across reboots. The steps mentioned above needs to be performed after every boot.

## Default Value

The actions in this recommendation refer to the `/home` partition, which is the default user partition that is defined in many distributions. If you have created other user partitions, it is recommended that the Remediation and Audit steps be applied to these partitions as well.

## CIS Controls

| Controls Version | Control                                                                                                                                                                                                                                         | IG 1 | IG 2 | IG 3 |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---- | ---- | ---- |
| v8               | 3.3 Configure Data Access Control Lists - Configure data access control lists based on a user's need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications. | x    | x    | x    |
| v7               | 5.1 Establish Secure Configurations - Maintain documented, standard security configuration standards for all authorized operating systems and software.                                                                                         | x    | x    | x    |

## Profile

Level 1 - Server | Automated

