Check: PHTN-67-000051
VMware vSphere 6.7 Photon OS STIG:
PHTN-67-000051
(in versions v1 r6 through v1 r1)
Title
The Photon operating system must protect audit tools from unauthorized modification. (Cat II impact)
Discussion
Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operations on audit information. Satisfies: SRG-OS-000257-GPOS-00098, SRG-OS-000258-GPOS-00099
Check Content
At the command line, execute the following command: # stat -c "%n permissions are %a" /usr/sbin/auditctl /usr/sbin/auditd /usr/sbin/aureport /usr/sbin/ausearch /usr/sbin/autrace If any file is more permissive than 750, this is a finding.
Fix Text
At the command line, execute the following command for each file returned: # chmod 750 <file>
Additional Identifiers
Rule ID: SV-239122r675174_rule
Vulnerability ID: V-239122
Group Title: SRG-OS-000257-GPOS-00098
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001494 |
The information system protects audit tools from unauthorized modification. |
CCI-001495 |
The information system protects audit tools from unauthorized deletion. |
Controls
Number | Title |
---|---|
AU-9 |
Protection Of Audit Information |