CIS Ubuntu 14.04 LTS - 5.4.3 Ensure default group for the root account is GID 0

Verify the root account default group is GID 0 to prevent root-owned files becoming accessible

cyberstrikeus Updated

File contents

5.4.3 Ensure default group for the root account is GID 0 (Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

The usermod command can be used to specify which group the root user belongs to. This affects permissions of files that are created by the root user.

Rationale

Using GID 0 for the root account helps prevent root-owned files from accidentally becoming accessible to non-privileged users.

Audit Procedure

Run the following command and verify the result is 0:

grep "^root:" /etc/passwd | cut -f4 -d:

Expected Result

0

Remediation

Run the following command to set the root user default group to GID 0:

usermod -g 0 root

Default Value

GID 0

References

  • CIS Controls: 5 - Controlled Use of Administration Privileges

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-5-4-3 commit a1746c5b65

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-5-4-3-ensure-default-group-for-the-root