SV-219234r610963_rule
V-219234
SRG-OS-000063-GPOS-00032
UBTU-18-010311
CAT II
10
Configure "/etc/audit/audit.rules", "/etc/audit/rules.d/*" and "/etc/audit/auditd.conf" files to have a mode of 0640 by using the following command:
# chmod -R 0640 /etc/audit/audit*.{rules,conf} /etc/audit/rules.d/*
Note: The "root" account must be used to edit any files in the /etc/audit and /etc/audit/rules.d/ directories.
Verify that "/etc/audit/audit.rules", "/etc/audit/rules.d/*" and "/etc/audit/auditd.conf" files have a mode of 0640 or less permissive by using the following command:
# sudo ls -al /etc/audit/ /etc/audit/rules.d/
/etc/audit/:
drwxr-x--- 3 root root 4096 Nov 25 11:02 .
drwxr-xr-x 130 root root 12288 Dec 19 13:42 ..
-rw-r----- 1 root root 804 Nov 25 11:01 auditd.conf
-rw-r----- 1 root root 9128 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 9373 Dec 27 09:56 audit.rules.prev
-rw-r----- 1 root root 127 Feb 7 2018 audit-stop.rules
drwxr-x--- 2 root root 4096 Dec 27 09:56 rules.d
/etc/audit/rules.d/:
drwxr-x--- 2 root root 4096 Dec 27 09:56 .
drwxr-x--- 3 root root 4096 Nov 25 11:02 ..
-rw-r----- 1 root root 10357 Dec 27 09:56 stig.rules
If "/etc/audit/audit.rule","/etc/audit/rules.d/*" or "/etc/audit/auditd.conf" file have a mode more permissive than "0640", this is a finding.
V-219234
False
UBTU-18-010311
Verify that "/etc/audit/audit.rules", "/etc/audit/rules.d/*" and "/etc/audit/auditd.conf" files have a mode of 0640 or less permissive by using the following command:
# sudo ls -al /etc/audit/ /etc/audit/rules.d/
/etc/audit/:
drwxr-x--- 3 root root 4096 Nov 25 11:02 .
drwxr-xr-x 130 root root 12288 Dec 19 13:42 ..
-rw-r----- 1 root root 804 Nov 25 11:01 auditd.conf
-rw-r----- 1 root root 9128 Dec 27 09:56 audit.rules
-rw-r----- 1 root root 9373 Dec 27 09:56 audit.rules.prev
-rw-r----- 1 root root 127 Feb 7 2018 audit-stop.rules
drwxr-x--- 2 root root 4096 Dec 27 09:56 rules.d
/etc/audit/rules.d/:
drwxr-x--- 2 root root 4096 Dec 27 09:56 .
drwxr-x--- 3 root root 4096 Nov 25 11:02 ..
-rw-r----- 1 root root 10357 Dec 27 09:56 stig.rules
If "/etc/audit/audit.rule","/etc/audit/rules.d/*" or "/etc/audit/auditd.conf" file have a mode more permissive than "0640", this is a finding.
M
4055