SV-270822r1134821_rule
V-270822
SRG-OS-000257-GPOS-00098
UBTU-24-901240
CAT II
10
Configure the audit tools on Ubuntu 24.04 LTS to be protected from unauthorized access by setting the file owner as root using the following command:
$ sudo chown root [audit_tool]
Replace "[audit_tool]" with each audit tool not owned by root.
Verify Ubuntu 24.04 LTS configures the audit tools to be owned by root to prevent any unauthorized access with the following command:
$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/augenrules root
If any of the audit tools are not owned by root, this is a finding.
V-270822
False
UBTU-24-901240
Verify Ubuntu 24.04 LTS configures the audit tools to be owned by root to prevent any unauthorized access with the following command:
$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/augenrules root
If any of the audit tools are not owned by root, this is a finding.
M
5673