SV-238302r654081_rule
V-238302
SRG-OS-000256-GPOS-00097
UBTU-20-010201
CAT II
10
Configure the audit tools on the Ubuntu operating system to be protected from unauthorized access by setting the file group as root using the following command:
$ sudo chown :root [audit_tool]
Replace "[audit_tool]" with each audit tool not group-owned by root.
Verify the Ubuntu operating system configures the audit tools to be group-owned by root to prevent any unauthorized access.
Check the group ownership by running the following command:
$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/audispd root
/sbin/augenrules root
If any of the audit tools are not group-owned by root, this is a finding.
V-238302
False
UBTU-20-010201
Verify the Ubuntu operating system configures the audit tools to be group-owned by root to prevent any unauthorized access.
Check the group ownership by running the following command:
$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules
/sbin/auditctl root
/sbin/aureport root
/sbin/ausearch root
/sbin/autrace root
/sbin/auditd root
/sbin/audispd root
/sbin/augenrules root
If any of the audit tools are not group-owned by root, this is a finding.
M
5318