September 2014
Intermediate to advanced
240 pages
5h 53m
English
To finish off, let's look at how to verify access privileges granted to users. Specifying roles and privileges allows users to do their job, but from a security point of view, it is also important to verify if (and which) users can manipulate certain resources. Auditors will want to have an overview of who is able to, say, manipulate SELinux policies or read private keys.
To properly investigate access rights, the following approach can help in identifying users (and processes) that have the permissions we want to be informed about:
Read now
Unlock full access