Check: OL6-00-000522
Oracle Linux 6 STIG:
OL6-00-000522
(in versions v2 r7 through v1 r9)
Title
Audit log files must be group-owned by root. (Cat II impact)
Discussion
If non-privileged users can write to audit logs, audit trails can be modified or destroyed.
Check Content
Run the following command to check the group owner of the system audit logs: grep "^log_file" /etc/audit/auditd.conf|sed s/^[^\/]*//|xargs stat -c %G:%n Audit logs must be group-owned by root. If they are not, this is a finding.
Fix Text
Change the group owner of the audit log files with the following command: # chgrp root [audit_file]
Additional Identifiers
Rule ID: SV-209066r793787_rule
Vulnerability ID: V-209066
Group Title: SRG-OS-000057
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000162 |
The information system protects audit information from unauthorized access. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AU-9 |
Protection Of Audit Information |