STIGUI
V-282641CAT II — Medium severitySV-282641r1200903_rule

TOSS 5 cron configuration directories must have a mode of 0700 or less permissive.

Rule version TOSS-05-000145 · STIG v1 · 2026-08-20

Discussion

Service configuration files enable or disable features of their respective services that if configured incorrectly can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the correct access rights to prevent unauthorized changes.

Check

Verify the permissions of the cron directories using the following command:

$ find /etc/cron* -type d | xargs stat -c "%a %n"

700 /etc/cron.d 700 /etc/cron.daily 700 /etc/cron.hourly 700 /etc/cron.monthly 700 /etc/cron.weekly

If any cron configuration directory is more permissive than "700", this is a finding.

Fix

Configure any TOSS 5 cron configuration directory with a mode more permissive than "0700" as follows:

$ sudo chmod 0700 [cron configuration directory]

Identifiers

Group ID
V-282641
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282641r1200903_rule
Check ID
C-87202r1200901_chk
Fix ID
F-87107r1200902_fix