SV-274877r1155381_rule
V-274877
SRG-OS-000471-GPOS-00215
RHEL-08-030655
CAT II
10
Configure RHEL 8 to audit the execution of any system call made by cron as root or as any privileged user.
Add or update the following file system rules to "/etc/audit/rules.d/audit.rules":
-w /etc/cron.d/ -p wa -k cronjobs
-w /var/spool/cron/ -p wa -k cronjobs
To load the rules to the kernel immediately, use the following command:
$ sudo augenrules --load
Verify RHEL 8 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
V-274877
False
RHEL-08-030655
Verify RHEL 8 is configured to audit the execution of any system call made by cron as root or as any privileged user.
$ sudo auditctl -l | grep /etc/cron.d
-w /etc/cron.d -p wa -k cronjobs
$ sudo auditctl -l | grep /var/spool/cron
-w /var/spool/cron -p wa -k cronjobs
If either of these commands do not return the expected output, or the lines are commented out, this is a finding.
M
2921