SV-274876r1156668_rule
V-274876
SRG-OS-000471-GPOS-00215
OL08-00-030645
CAT II
10
Configure OL 8 to audit the execution of any system call made by cron as root or as any privileged user.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
-w /etc/cron.d/ -p wa -k cronjobs
-w /var/spool/cron/ -p wa -k cronjobs
To load the rules to the kernel immediately, use the following command:
$ sudo augenrules --load
Verify OL 8 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
V-274876
False
OL08-00-030645
Verify OL 8 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
M
5416