STIGQter STIGQter: STIG Summary: Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Jul 2026:

Ubuntu 24.04 LTS must permit only authorized accounts to own the audit configuration files.

DISA Rule

SV-270776r1066817_rule

Vulnerability Number

V-270776

Group Title

SRG-OS-000063-GPOS-00032

Rule Version

UBTU-24-900050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure /etc/audit/audit.rules, /etc/audit/rules.d/*, and /etc/audit/auditd.conf files to be owned by "root" user by using the following command:

$ sudo chown root /etc/audit/audit*.{rules,conf} /etc/audit/rules.d/*

Check Contents

Verify /etc/audit/audit.rules, /etc/audit/rules.d/*, and /etc/audit/auditd.conf files are owned by "root" account with the following command:

$ sudo ls -al /etc/audit/ /etc/audit/rules.d/
/etc/audit/:

-rw-r----- 1 root root 804 Nov 25 11:01 auditd.conf
-rw-r----- 1 root root 9128 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 127 Feb 7 2018 audit-stop.rules

drwxr-x--- 2 root root 4096 Dec 27 09:56 rules.d

/etc/audit/rules.d/:

-rw-r----- 1 root root 244 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 10357 Dec 27 09:56 stig.rules

If the /etc/audit/audit.rules, /etc/audit/rules.d/*, or /etc/audit/auditd.conf file is owned by a user other than "root", this is a finding.

Vulnerability Number

V-270776

Documentable

False

Rule Version

UBTU-24-900050

Severity Override Guidance

Verify /etc/audit/audit.rules, /etc/audit/rules.d/*, and /etc/audit/auditd.conf files are owned by "root" account with the following command:

$ sudo ls -al /etc/audit/ /etc/audit/rules.d/
/etc/audit/:

-rw-r----- 1 root root 804 Nov 25 11:01 auditd.conf
-rw-r----- 1 root root 9128 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 127 Feb 7 2018 audit-stop.rules

drwxr-x--- 2 root root 4096 Dec 27 09:56 rules.d

/etc/audit/rules.d/:

-rw-r----- 1 root root 244 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 10357 Dec 27 09:56 stig.rules

If the /etc/audit/audit.rules, /etc/audit/rules.d/*, or /etc/audit/auditd.conf file is owned by a user other than "root", this is a finding.

Check Content Reference

M

Target Key

5673