Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
DISA Rule
SV-274085r1120243_rule
Vulnerability Number
V-274085
Group Title
SRG-OS-000004-GPOS-00004
Rule Version
AZLX-23-002105
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-002130 - Automatically audit account enabling actions.
Weight
10
Fix Recommendation
Configure Amazon Linux 2023 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/security/opasswd".
Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":
-w /etc/security/opasswd -p wa -k identity
To load the rules to the kernel immediately, use the following command:
$ sudo augenrules --load
Check Contents
Verify Amazon Linux 2023 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/security/opasswd" with the following command:
$ sudo auditctl -l | egrep '(/etc/security/opasswd)'
-w /etc/security/opasswd -p wa -k identity
If the command does not return a line, or the line is commented out, this is a finding.
Vulnerability Number
V-274085
Documentable
False
Rule Version
AZLX-23-002105
Severity Override Guidance
Verify Amazon Linux 2023 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/security/opasswd" with the following command:
$ sudo auditctl -l | egrep '(/etc/security/opasswd)'
-w /etc/security/opasswd -p wa -k identity
If the command does not return a line, or the line is commented out, this is a finding.
Check Content Reference
M
Target Key
5700