5.3.8 Record Events That Modify User/Group Information '/etc/gshadow'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.-w /etc/group -p wa -k identity
-w /etc/passwd -p wa -k identity
-w /etc/gshadow -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/security/opasswd -p wa -k identity
# Execute the following command to restart auditd
# pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14829-6

Plugin: Unix

Control ID: b64277b675732918bb7e59dee31176570b3e025c564306a9392d57f16179b02a