SV-275601r1147853_rule
V-275601
SRG-OS-000256-GPOS-00097
RIIM-OS-232110
CAT II
10
Configure the audit tools on Ubuntu OS to be protected from unauthorized access by setting the file owner as root using the following command:
$ sudo chown root <audit_tool_name>
Replace "<audit_tool_name>" with each audit tool not owned by "root".
Verify Ubuntu OS configures the audit tools to be owned by "root" to prevent any unauthorized access with the following command:
$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/audispd-zos-remote root
/sbin/augenrules root
If any of the audit tools are not owned by "root", this is a finding.
V-275601
False
RIIM-OS-232110
Verify Ubuntu OS configures the audit tools to be owned by "root" to prevent any unauthorized access with the following command:
$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd* /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/audispd-zos-remote root
/sbin/augenrules root
If any of the audit tools are not owned by "root", this is a finding.
M
5706