TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
DISA Rule
SV-282359r1200057_rule
Vulnerability Number
V-282359
Group Title
SRG-OS-000004-GPOS-00004
Rule Version
TOSS-05-000458
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
Configure TOSS 5 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow".
Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":
-w /etc/shadow -p wa -k identity
Restart the audit daemon for the changes to take effect.
Check Contents
Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd using the following command:
$ sudo auditctl -l | egrep '(/etc/shadow)'
-w /etc/shadow -p wa -k identity
If the command does not return a line or the line is commented out, this is a finding.
Vulnerability Number
V-282359
Documentable
False
Rule Version
TOSS-05-000458
Severity Override Guidance
Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd using the following command:
$ sudo auditctl -l | egrep '(/etc/shadow)'
-w /etc/shadow -p wa -k identity
If the command does not return a line or the line is commented out, this is a finding.
Check Content Reference
M
Target Key
5738