SV-282423r1201569_rule
V-282423
SRG-OS-000037-GPOS-00015
TOSS-05-000451
CAT II
10
Configure the audit system to generate an audit event for any successful/unsuccessful use of the "umount2" system call by adding or updating the following rules in "/etc/audit/audit.rules" and adding the following rules to "/etc/audit/rules.d/perm_mod.rules" or updating the existing rules in files in the "/etc/audit/rules.d/" directory:
-a always,exit -F arch=b32 -S umount2 -F auid>=1000 -F auid!=unset -k perm_mod
-a always,exit -F arch=b64 -S umount2 -F auid>=1000 -F auid!=unset -k perm_mod
Restart the audit daemon for changes to take effect.
To determine if the system is configured to audit calls to the umount2 system call, run the following command:
$ sudo grep "umount2" /etc/audit/audit.*
If no line is returned, this is a finding.
V-282423
False
TOSS-05-000451
To determine if the system is configured to audit calls to the umount2 system call, run the following command:
$ sudo grep "umount2" /etc/audit/audit.*
If no line is returned, this is a finding.
M
5738