SV-221814r603260_rule
V-221814
SRG-OS-000042-GPOS-00020
OL07-00-030750
CAT II
10
Configure the operating system to generate audit records when successful/unsuccessful attempts to use the "umount" command occur.
Add or update the following rule in "/etc/audit/rules.d/audit.rules":
-a always,exit -F path=/usr/bin/umount -F auid>=1000 -F auid!=unset -k privileged-mount
The audit daemon must be restarted for the changes to take effect.
Verify the operating system generates audit records when successful/unsuccessful attempts to use the "umount" command occur.
Check that the following system call is being audited by performing the following series of commands to check the file system rules in "/etc/audit/audit.rules":
# grep -iw "/usr/bin/umount" /etc/audit/audit.rules
-a always,exit -F path=/usr/bin/umount -F auid>=1000 -F auid!=unset -k privileged-mount
If the command does not return any output, this is a finding.
V-221814
False
OL07-00-030750
Verify the operating system generates audit records when successful/unsuccessful attempts to use the "umount" command occur.
Check that the following system call is being audited by performing the following series of commands to check the file system rules in "/etc/audit/audit.rules":
# grep -iw "/usr/bin/umount" /etc/audit/audit.rules
-a always,exit -F path=/usr/bin/umount -F auid>=1000 -F auid!=unset -k privileged-mount
If the command does not return any output, this is a finding.
M
4089