Xylok Security Suite must protect audit information from any type of unauthorized access.
DISA Rule
SV-269576r1053503_rule
Vulnerability Number
V-269576
Group Title
SRG-APP-000118
Rule Version
XYLK-20-000043
Severity
CAT II
CCI(s)
- CCI-000162 - Protect audit information from unauthorized access.
- CCI-000163 - Protect audit information from unauthorized modification.
- CCI-000164 - Protect audit information from unauthorized deletion.
- CCI-001493 - Protect audit tools from unauthorized access.
- CCI-001494 - Protect audit tools from unauthorized modification.
- CCI-001495 - Protect audit tools from unauthorized deletion.
Weight
10
Fix Recommendation
As root, remove all global permissions for Xylok's log files by running:
# chmod -R 0770 /var/log/xylok/
Check Contents
Check the Xylok log file directory permissions with the following command:
$ ls -l /var/log/xylok
If any of the directories have permissions greater than "0770", this is a finding.
Vulnerability Number
V-269576
Documentable
False
Rule Version
XYLK-20-000043
Severity Override Guidance
Check the Xylok log file directory permissions with the following command:
$ ls -l /var/log/xylok
If any of the directories have permissions greater than "0770", this is a finding.
Check Content Reference
M
Target Key
5665