1.3.2 Ensure filesystem integrity is regularly checked

Information

Periodic checking of the filesystem integrity is needed to detect changes to the filesystem. Periodic file checking allows the system administrator to determine on a regular basis if critical files have been changed in an unauthorized fashion.

Solution

Run the following command: # crontab -u root -e Add the following line to the crontab: 0 5 * * * /usr/sbin/aide --check Notes - The checking in this recommendation occurs every day at 5am. Alter the frequency and time of the checks in compliance with site policy.

See Also

https://workbench.cisecurity.org/files/2171

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1), CSCv7|14.9

Plugin: Unix

Control ID: d0b90308be3ce9f5bb5f23ce69fed3fadc5790f993dbacb8bcfb03bf02bf4f5f