Rule ID
SV-45602r1_rule
Version
V1R12
CCIs
To protect the integrity of scheduled system jobs and to prevent malicious modification to these jobs, crontab files must be secured.
Check the mode of the crontab directories.
Procedure:
# ls -ld /var/spool/cron /var/spool/cron/tabs
ls -ld /etc/crontab /etc/cron.{d,daily,hourly,monthly,weekly}
or
# ls -ld /etc/cron*|grep -v deny
If the mode of any of the crontab directories is more permissive than 0755, this is a finding.Change the mode of the crontab directories. # chmod 0755 <crontab directory>