Check: RHEL-09-232104
RHEL 9 STIG:
RHEL-09-232104
(in version v2 r3)
Title
RHEL 9 "/etc/audit/" must be group-owned by root. (Cat II impact)
Discussion
The "/etc/audit/" directory contains files that ensure the proper auditing of command execution, privilege escalation, file manipulation, and more. Protection of this directory is critical for system security.
Check Content
Verify the group ownership of the "/etc/audit/" directory with the following command: $ sudo stat -c "%G %n" /etc/audit/ root /etc/audit/ If "/etc/audit/" does not have a group owner of "root", this is a finding.
Fix Text
Change the group of the file "/etc/audit/" to "root" by running the following command: $ sudo chgrp root /etc/audit/
Additional Identifiers
Rule ID: SV-270176r1044967_rule
Vulnerability ID: V-270176
Group Title: SRG-OS-000080-GPOS-00048
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000162 |
Protect audit information from unauthorized access. |
Controls
Number | Title |
---|---|
AU-9 |
Protection of Audit Information |