SV-275586r1147808_rule
V-275586
SRG-OS-000256-GPOS-00097
RIIM-OS-232035
CAT II
10
Configure the audit tools on Ubuntu OS to be protected from unauthorized access by setting the correct permissive mode using the following command:
$ sudo chmod 755 <audit_tool_name>
Replace "<audit_tool_name>" with the audit tool that does not have the correct permissions.
Verify Ubuntu OS configures the audit tools to have a file permission of "755" or less to prevent unauthorized access by using the following command:
$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl 755
/sbin/aureport 755
/sbin/ausearch 755
/sbin/autrace 755
/sbin/auditd 755
/sbin/audispd-zos-remote 755
/sbin/augenrules 755
If any of the audit tools have a mode more permissive than "0755", this is a finding.
V-275586
False
RIIM-OS-232035
Verify Ubuntu OS configures the audit tools to have a file permission of "755" or less to prevent unauthorized access by using the following command:
$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl 755
/sbin/aureport 755
/sbin/ausearch 755
/sbin/autrace 755
/sbin/auditd 755
/sbin/audispd-zos-remote 755
/sbin/augenrules 755
If any of the audit tools have a mode more permissive than "0755", this is a finding.
M
5706