Checklist for Unix Server and Auditing Account Management and Password Controls

Review and evaluate procedures for creating Unix or Linux user accounts and ensure that accounts are created only when there's a legitimate business need. Also review and evaluate processes for ensuring that accounts are removed or disabled in a timely fashion in the event of termination or job change.
Ensure that all UID's in the password file(s) are unique.
Ensure that passwords are shadowed and use strong hashes where possible.
Evaluate the file permissions for the password and shadow password files.
Review and evaluate the strength of system passwords.
Evaluate the use of password controls such as aging.
Review the process used by the system administrator(s) for setting initial passwords for new users and communicating those passwords.
| Free Download Attachment | Size |
|---|---|
| ChecklistforAuditing-Unix.xls | 21 KB |








