SV-230779r599842_rule
V-230779
SRG-OS-000057-GPOS-00027
APPL-11-001017
CAT II
10
For any log folder that returns an incorrect permission value, run the following command:
/usr/bin/sudo chmod 700 [audit log folder]
To check the permissions of the audit log folder, run the following command:
/usr/bin/sudo ls -lde $(/usr/bin/sudo /usr/bin/grep '^dir' /etc/security/audit_control | awk -F: '{print $2}')
The results should show the permissions (first column) to be "700" or less permissive.
If they do not, this is a finding.
V-230779
False
APPL-11-001017
To check the permissions of the audit log folder, run the following command:
/usr/bin/sudo ls -lde $(/usr/bin/sudo /usr/bin/grep '^dir' /etc/security/audit_control | awk -F: '{print $2}')
The results should show the permissions (first column) to be "700" or less permissive.
If they do not, this is a finding.
M
5246