5.3.8 Record Events That Modify User/Group Information '/etc/group'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.-w /etc/group -p wa -k identity
-w /etc/passwd -p wa -k identity
-w /etc/gshadow -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/security/opasswd -p wa -k identity
# Execute the following command to restart auditd
# pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14829-6

Plugin: Unix

Control ID: abb834de6e8f34399ebb3c193d4c02a0b985de17cfabd21aad6c4dce37ea6b5c