Check: GEN001260
HP-UX 11.23 STIG:
GEN001260
(in version v1 r8)
Title
System log files must have mode 0640 or less permissive. (Cat II impact)
Discussion
If the system log files are not protected, unauthorized users could change the logged data, eliminating its forensic value.
Check Content
Check the mode of log files. # ls -lLR /var/log /var/log/syslog /var/adm /var/opt Note that some of the above directories will contain more than just system log files. For example: /var/adm/sa, /var/adm/sw, etc. Any non-system log files contained within the above directories should be excluded from this requirement. If any of the system log files have modes more permissive than 0640, this is a finding.
Fix Text
Change the mode of the system log files to 0640 or less permissive. # chmod 0640 <path>/<system-log-file> NOTE: Do not confuse system log files with audit logs.
Additional Identifiers
Rule ID: SV-35275r1_rule
Vulnerability ID: V-787
Group Title: GEN001260
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001314 |
The information system reveals error messages only to organization-defined personnel or roles. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |