SV-269460r1050343_rule
V-269460
SRG-OS-000063-GPOS-00032
ALMA-09-045890
CAT II
10
Configure the "/etc/audit/rules.d/*.rules", "/etc/audit/audit.rules" and "/etc/audit/auditd.conf" files to have a mode of "0640" with the following command:
$ chmod 0640 /etc/audit/rules.d/*.rules /etc/audit/auditd.conf /etc/audit/audit.rules
Verify that the following files have a mode of "0640" or less permissive with the following command:
$ stat -c "%U:%G %#a %n" /etc/audit/rules.d/*.rules /etc/audit/audit.rules /etc/audit/auditd.conf
root:root 0600 /etc/audit/rules.d/audit.rules
root:root 0640 /etc/audit/audit.rules
root:root 0640 /etc/audit/auditd.conf
If the files file have a mode more permissive than "0640", this is a finding.
V-269460
False
ALMA-09-045890
Verify that the following files have a mode of "0640" or less permissive with the following command:
$ stat -c "%U:%G %#a %n" /etc/audit/rules.d/*.rules /etc/audit/audit.rules /etc/audit/auditd.conf
root:root 0600 /etc/audit/rules.d/audit.rules
root:root 0640 /etc/audit/audit.rules
root:root 0640 /etc/audit/auditd.conf
If the files file have a mode more permissive than "0640", this is a finding.
M
5664