SV-230473r627750_rule
V-230473
SRG-OS-000256-GPOS-00097
RHEL-08-030630
CAT II
10
Configure the audit tools to be owned by "root", by running the following command:
$ sudo chown root [audit_tool]
Replace "[audit_tool]" with each audit tool not owned by "root".
Verify the audit tools are owned by "root" to prevent any unauthorized access, deletion, or modification.
Check the owner of each audit tool by running the following command:
$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslog /sbin/augenrules
root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
If any of the audit tools are not owned by "root", this is a finding.
V-230473
False
RHEL-08-030630
Verify the audit tools are owned by "root" to prevent any unauthorized access, deletion, or modification.
Check the owner of each audit tool by running the following command:
$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslog /sbin/augenrules
root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
If any of the audit tools are not owned by "root", this is a finding.
M
2921