RHEL 8 must use a separate file system for /var.

STIG ID: RHEL-08-010540  |  SRG: SRG-OS-000480-GPOS-00227 | Severity: low |  CCI: CCI-000366

Vulnerability Discussion

The use of separate file systems for different paths can protect the system from failures resulting from a file system becoming full or failing.

Check

Verify that a separate file system has been created for "/var".

Check that a file system has been created for "/var" with the following command:

$ sudo grep /var /etc/fstab

/dev/mapper/... /var xfs defaults,nodev 0 0

If a separate entry for "/var" is not in use, this is a finding.

Fix

Migrate the "/var" path onto a separate file system.