SV-204552r603261_rule
V-204552
SRG-OS-000042-GPOS-00020
RHEL-07-030740
CAT II
10
Configure the operating system to generate audit records when successful/unsuccessful attempts to use the "mount" command and syscall occur.
Add or update the following rules in "/etc/audit/rules.d/audit.rules":
-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F path=/usr/bin/mount -F auid>=1000 -F auid!=unset -k privileged-mount
The audit daemon must be restarted for the changes to take effect.
Verify the operating system generates audit records when successful/unsuccessful attempts to use the "mount" command and syscall occur.
Check that the following system call is being audited by performing the following series of commands to check the file system rules in "/etc/audit/audit.rules":
# grep -iw "mount" /etc/audit/audit.rules
-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F path=/usr/bin/mount -F auid>=1000 -F auid!=unset -k privileged-mount
If both the "b32" and "b64" audit rules are not defined for the "mount" syscall, this is a finding.
If all uses of the "mount" command are not being audited, this is a finding.
V-204552
False
RHEL-07-030740
Verify the operating system generates audit records when successful/unsuccessful attempts to use the "mount" command and syscall occur.
Check that the following system call is being audited by performing the following series of commands to check the file system rules in "/etc/audit/audit.rules":
# grep -iw "mount" /etc/audit/audit.rules
-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=unset -k privileged-mount
-a always,exit -F path=/usr/bin/mount -F auid>=1000 -F auid!=unset -k privileged-mount
If both the "b32" and "b64" audit rules are not defined for the "mount" syscall, this is a finding.
If all uses of the "mount" command are not being audited, this is a finding.
M
2899