Check: OSX8-00-00215
Apple OSX 10.8 STIG:
OSX8-00-00215
(in version v1 r2)
Title
The audit log folder must be owned by root:wheel. (Cat II impact)
Discussion
Non-repudiation of actions taken is required in order to maintain integrity. To do this, we will prevent users from modifying the audit logs. Non-repudiation protects individuals against later claims by an author of not having updated a particular file, invoked a specific command, or copied a specific file.
Check Content
To check the ownership of the audit log files, run the following command: sudo -s ls -dn `sudo grep "^dir" /etc/security/audit_control | awk -F: '{print $2}'`| awk '{ print $3 ":" $4 }' The results should be "0:0". This command shows the UID and GID of the audit logs directory. With the first "0" being root, and the second "0" being wheel. If there is any other result, this is a finding.
Fix Text
If the audit log folder is not owned by root:wheel, run the following command: sudo chown root:wheel /var/audit
Additional Identifiers
Rule ID: SV-65869r1_rule
Vulnerability ID: V-51659
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000166 |
The information system protects against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation. |
Controls
Number | Title |
---|---|
AU-10 |
Non-Repudiation |