SV-274874r1101856_rule
V-274874
SRG-OS-000471-GPOS-00215
ALMA-09-048865
CAT II
10
Configure AlmaLinux OS 9 to audit the execution of any system call made by cron as root or as any privileged user.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
auditctl -w /etc/cron.d/ -p wa -k cronjobs
auditctl -w /var/spool/cron/ -p wa -k cronjobs
To load the rules to the kernel immediately, use the following command:
$ sudo augenrules --load
Verify that AlmaLinux OS 9 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
V-274874
False
ALMA-09-048865
Verify that AlmaLinux OS 9 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
M
5664