Check: GEN002710
VMware ESX 3 Server:
GEN002710
(in version v1 r2)
Title
All system audit files must not have extended ACLs. (Cat II impact)
Discussion
If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.
Check Content
Determine if system audit files have an extended ACL. If any do, this is a finding.
Fix Text
Remove the extended ACL from the system audit file(s).
Additional Identifiers
Rule ID: SV-26016r1_rule
Vulnerability ID: V-22369
Group Title: GEN002710
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000163 |
The information system protects audit information from unauthorized modification. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AU-9 |
Protection Of Audit Information |