5.3.8 Record Events That Modify User/Group Information '/etc/passwd'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.-w /etc/group -p wa -k identity
-w /etc/passwd -p wa -k identity
-w /etc/gshadow -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/security/opasswd -p wa -k identity
# Execute the following command to restart auditd
# pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14829-6

Plugin: Unix

Control ID: 91b461049e1083f29d2608efe12cebd7ec2e3749cd908574d08a33605c1e5896