OL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
DISA Rule
SV-271530r1092480_rule
Vulnerability Number
V-271530
Group Title
SRG-OS-000004-GPOS-00004
Rule Version
OL09-00-000515
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-002130 - Automatically audit account enabling actions.
Weight
10
Fix Recommendation
Configure OL 9 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow".
Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":
-w /etc/gshadow -p wa -k identity
The audit daemon must be restarted for the changes to take effect.
Restart auditd:
$ sudo service auditd restart
Check Contents
Verify that OL 9 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow" with the following command:
$ sudo auditctl -l | egrep '(/etc/gshadow)'
-w /etc/gshadow -p wa -k identity
If the command does not return a line or the line is commented out, this is a finding.
Vulnerability Number
V-271530
Documentable
False
Rule Version
OL09-00-000515
Severity Override Guidance
Verify that OL 9 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow" with the following command:
$ sudo auditctl -l | egrep '(/etc/gshadow)'
-w /etc/gshadow -p wa -k identity
If the command does not return a line or the line is commented out, this is a finding.
Check Content Reference
M
Target Key
5680