Check: GEN000000-IRIX00080
IRIX 6.5:
GEN000000-IRIX00080
(in versions v1 r1 through v1 r0.6)
Title
The /etc/config/sat_select.options file must be group-owned by root. (Cat II impact)
Discussion
The IRIX sat_select.options file allows for selective auditing or non-auditing of features for certain users. If it is not protected, it could be compromised and used to mask audit events. This could cause the loss of valuable forensics data in the case of a system compromise.
Check Content
Check /etc/config/sat_select.options group ownership. # ls -lL /etc/config If /etc/config/sat_select.options file is not group owned by root, this is a finding.
Fix Text
Change the group owner of the sat_select.options file to root.
Additional Identifiers
Rule ID:
Vulnerability ID: V-4351
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |