SV-219197r610963_rule
V-219197
SRG-OS-000256-GPOS-00097
UBTU-18-010130
CAT II
10
Configure the audit tools on the Ubuntu operating system to be group-owned by root, by running the following command:
# sudo chgrp root [audit_tool]
Replace "[audit_tool]" with each audit tool not group-owned by root.
Verify the Ubuntu operating system configures the audit tools to be group-owned by root to prevent any unauthorized access, deletion, or modification.
For each audit tools,
/sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules
Check the group-owner of each audit tool by running the following commands:
stat -c "%n %G" /sbin/auditctl
/sbin/auditctl root
If any of the audit tools are not group-owned by root, this is a finding.
V-219197
False
UBTU-18-010130
Verify the Ubuntu operating system configures the audit tools to be group-owned by root to prevent any unauthorized access, deletion, or modification.
For each audit tools,
/sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules
Check the group-owner of each audit tool by running the following commands:
stat -c "%n %G" /sbin/auditctl
/sbin/auditctl root
If any of the audit tools are not group-owned by root, this is a finding.
M
4055