SV-227045r603265_rule
V-227045
SRG-OS-000445
GEN006570
CAT III
10
If using AIDE, edit the configuration and add the acl option for all monitored files and directories.
If using a different file integrity tool, configure ACL checking per the tool's documentation.
If using AIDE, verify the configuration contains the acl option for all monitored files and directories. Here is an example AIDE configuration fragment.
SampleRule = p+i+l+n+u+g+s+m+c+acl+xattrs+sha256
/bin SampleRule
If the acl option is not present, this is a finding.
If using a different file integrity tool, check the configuration per tool documentation.
V-227045
False
GEN006570
If using AIDE, verify the configuration contains the acl option for all monitored files and directories. Here is an example AIDE configuration fragment.
SampleRule = p+i+l+n+u+g+s+m+c+acl+xattrs+sha256
/bin SampleRule
If the acl option is not present, this is a finding.
If using a different file integrity tool, check the configuration per tool documentation.
M
4060