SV-226590r603265_rule
V-226590
SRG-OS-000057
GEN002680
CAT II
10
Change the ownership of the audit log file(s).
Procedure:
# chown root <audit log file>
Perform the following to determine the location of audit logs and then check the ownership.
# more /etc/security/audit_control
# ls -lLa <audit log dir>
If any audit log file is not owned by root, this is a finding.
V-226590
False
GEN002680
Perform the following to determine the location of audit logs and then check the ownership.
# more /etc/security/audit_control
# ls -lLa <audit log dir>
If any audit log file is not owned by root, this is a finding.
M
4060