SV-208892r603263_rule
V-208892
SRG-OS-000480
OL6-00-000183
CAT III
10
Add the following to "/etc/audit/audit.rules":
-w /etc/selinux/ -p wa -k MAC-policy
To determine if the system is configured to audit changes to its SELinux configuration files, run the following command:
$ sudo grep -w "/etc/selinux" /etc/audit/audit.rules
If the system is configured to watch for changes to its SELinux configuration, a line should be returned (including "-p wa" indicating permissions that are watched).
If the system is not configured to audit attempts to change the MAC policy, this is a finding.
V-208892
False
OL6-00-000183
To determine if the system is configured to audit changes to its SELinux configuration files, run the following command:
$ sudo grep -w "/etc/selinux" /etc/audit/audit.rules
If the system is configured to watch for changes to its SELinux configuration, a line should be returned (including "-p wa" indicating permissions that are watched).
If the system is not configured to audit attempts to change the MAC policy, this is a finding.
M
2928