4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected

Information

Changes to files in these directories could indicate that an unauthorized user is attempting to modify access controls and change security contexts, leading to a compromise of the system.

Solution

Add the following line to the /etc/audit/audit.rules file: -w /etc/selinux/ -p wa -k MAC-policy

See Also

https://benchmarks.cisecurity.org/tools2/linux/CIS_Amazon_Linux_Benchmark_v2.0.0.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: 7bcd647d14d100617d8943437d741f468ffb5eebfcd5b79160c61a0a425a3fe4