5.3.10 Record Events That Modify the System's Mandatory Access Controls '/etc/selinux/'

Information

Configuration Level : Level-II

Solution

Add the following lines to the /etc/audit/audit.rules file.Add the following lines to /etc/audit/audit.rules
-w /etc/selinux/ -p wa -k MAC-policy
# Execute the following command to restart auditd
# pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CCE|CCE-14821-3

Plugin: Unix

Control ID: 17db013dec5d76beeef306dd6cf72ad230e7970592dc7880199024d92e31c4a8