STIGQter STIGQter: STIG Summary: Solaris 10 SPARC Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

System audit tool executables must not have extended ACLs.

DISA Rule

SV-226597r603265_rule

Vulnerability Number

V-226597

Group Title

SRG-OS-000256

Rule Version

GEN002718

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Remove the extended ACL from the file.
# chmod A- [audit file]

Check Contents

Check the permissions of audit tool executables.
# ls -l /usr/sbin/auditd /usr/sbin/audit /usr/sbin/bsmrecord /usr/sbin/auditreduce /usr/sbin/praudit /usr/sbin/auditconfig
If the permissions include a "+", the file has an extended ACL and this is a finding.

Vulnerability Number

V-226597

Documentable

False

Rule Version

GEN002718

Severity Override Guidance

Check the permissions of audit tool executables.
# ls -l /usr/sbin/auditd /usr/sbin/audit /usr/sbin/bsmrecord /usr/sbin/auditreduce /usr/sbin/praudit /usr/sbin/auditconfig
If the permissions include a "+", the file has an extended ACL and this is a finding.

Check Content Reference

M

Target Key

4060

Comments