SV-239124r675180_rule
V-239124
SRG-OS-000278-GPOS-00108
PHTN-67-000053
CAT II
10
If the audit system binaries have been altered, the system must be taken offline and the ISSM must be notified immediately.
Reinstalling the audit tools is not supported.
The appliance should be restored from a backup or a snapshot or redeployed once the root cause is remediated.
Use the verification capability of rpm to check the MD5 hashes of the audit files on disk versus the expected ones from the installation package.
At the command line, execute the following command:
# rpm -V audit | grep "^..5" | grep -v "^...........c"
If there is output, this is a finding.
V-239124
False
PHTN-67-000053
Use the verification capability of rpm to check the MD5 hashes of the audit files on disk versus the expected ones from the installation package.
At the command line, execute the following command:
# rpm -V audit | grep "^..5" | grep -v "^...........c"
If there is output, this is a finding.
M
5323