Check: RHEL-09-232103
RHEL 9 STIG:
RHEL-09-232103
(in version v2 r3)
Title
RHEL 9 "/etc/audit/" must be owned by root. (Cat II impact)
Discussion
The "/etc/audit/" directory contains files that ensure the proper auditing of command execution, privilege escalation, file manipulation, and more. Protection of this directory is critical for system security.
Check Content
Verify the ownership of the "/etc/audit/" directory with the following command: $ sudo stat -c "%U %n" /etc/audit/ root /etc/audit/ If the "/etc/audit/" directory does not have an owner of "root", this is a finding.
Fix Text
Change the owner of the file "/etc/audit/" to "root" by running the following command: $ sudo chown root /etc/audit/
Additional Identifiers
Rule ID: SV-270175r1044964_rule
Vulnerability ID: V-270175
Group Title: SRG-OS-000080-GPOS-00048
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000162 |
Protect audit information from unauthorized access. |
Controls
Number | Title |
---|---|
AU-9 |
Protection of Audit Information |