Check: 2.001
Windows XP STIG:
2.001
(in versions v6 r1.32 through v1 r0)
Title
ACLs for event logs do not conform to minimum requirements. (Cat II impact)
Discussion
Event logs are susceptible to unauthorized, and possibly anonymous, tampering if proper ACLs are not applied.
Check Content
The event log files “AppEvent.Evt,” “SecEvent.Evt,” and “SysEvent.Evt”— by default, all found in the “%SystemRoot%\SYSTEM32\CONFIG” directory. They may have been moved to another folder. Check for the following permissions: Administrators RX (Auditor’s group) All SYSTEM All Note: See V-1137 for the Auditors group requirement. The “Auditors” group may appear in the Gold Disk output as a finding. This is because the name of the group is left to the sites. If an auditors group is present, its presence doesn’t constitute a finding. If the permissions for these files are not as restrictive as the ACL listed, then this is a finding.
Fix Text
Set the ACL permissions on the event logs as defined in the manual check.
Additional Identifiers
Rule ID: SV-29199r1_rule
Vulnerability ID: V-1077
Group Title: Incorrect ACLs for event logs
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |