SV-270823r1134824_rule
V-270823
SRG-OS-000257-GPOS-00098
UBTU-24-901250
CAT II
10
Configure the audit tools on Ubuntu 24.04 LTS to be protected from unauthorized access by setting the file group as root using the following command:
$ sudo chown :root [audit_tool]
Replace "[audit_tool]" with each audit tool not group owned by root.
Verify Ubuntu 24.04 LTS configures the audit tools to be group owned by root to prevent any unauthorized access with the following command:
$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/augenrules root
If any of the audit tools are not group owned by root, this is a finding.
V-270823
False
UBTU-24-901250
Verify Ubuntu 24.04 LTS configures the audit tools to be group owned by root to prevent any unauthorized access with the following command:
$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/augenrules root
If any of the audit tools are not group owned by root, this is a finding.
M
5673