SV-282739r1201595_rule
V-282739
SRG-OS-000480-GPOS-00227
TOSS-05-000343
CAT II
10
Configure TOSS 5 to not allow users to execute privileged actions without authenticating with a password.
Remove any occurrence of "NOPASSWD" found in "/etc/sudoers" file or files in the "/etc/sudoers.d" directory.
$ sudo sed -i '/NOPASSWD/ s/^/# /g' /etc/sudoers /etc/sudoers.d/*
Verify "/etc/sudoers" has no occurrences of "NOPASSWD" using the following command:
$ sudo grep -ri nopasswd /etc/sudoers /etc/sudoers.d/*
If any occurrences of "NOPASSWD" are returned and this is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
V-282739
False
TOSS-05-000343
Verify "/etc/sudoers" has no occurrences of "NOPASSWD" using the following command:
$ sudo grep -ri nopasswd /etc/sudoers /etc/sudoers.d/*
If any occurrences of "NOPASSWD" are returned and this is not documented with the information system security officer (ISSO) as an operational requirement, this is a finding.
M
5738