SV-253022r991557_rule
V-253022
SRG-OS-000256-GPOS-00097
TOSS-04-030750
CAT II
10
Configure the audit tools to be owned by "root", by running the following command:
$ sudo chown root [audit_tool]
Replace "[audit_tool]" with each audit tool not owned by "root".
Verify the audit tools are owned by "root" to prevent any unauthorized access, deletion, or modification.
Check the owner of each audit tool by running the following command:
$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslogd /sbin/augenrules
root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
If any of the audit tools are not owned by "root", this is a finding.
V-253022
False
TOSS-04-030750
Verify the audit tools are owned by "root" to prevent any unauthorized access, deletion, or modification.
Check the owner of each audit tool by running the following command:
$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslogd /sbin/augenrules
root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
If any of the audit tools are not owned by "root", this is a finding.
M
5469