SV-260492r991557_rule
V-260492
SRG-OS-000256-GPOS-00097
UBTU-22-232035
CAT II
10
Configure the audit tools on Ubuntu 22.04 LTS to be protected from unauthorized access by setting the correct permissive mode using the following command:
$ sudo chmod 755 <audit_tool_name>
Replace "<audit_tool_name>" with the audit tool that does not have the correct permissions.
Verify Ubuntu 22.04 LTS configures the audit tools to have a file permission of "755" or less to prevent unauthorized access by using the following command:
$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl 755
/sbin/aureport 755
/sbin/ausearch 755
/sbin/autrace 755
/sbin/auditd 755
/sbin/audispd-zos-remote 755
/sbin/augenrules 755
If any of the audit tools have a mode more permissive than "0755", this is a finding.
V-260492
False
UBTU-22-232035
Verify Ubuntu 22.04 LTS configures the audit tools to have a file permission of "755" or less to prevent unauthorized access by using the following command:
$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl 755
/sbin/aureport 755
/sbin/ausearch 755
/sbin/autrace 755
/sbin/auditd 755
/sbin/audispd-zos-remote 755
/sbin/augenrules 755
If any of the audit tools have a mode more permissive than "0755", this is a finding.
M
5594