1.2.7 Verify Package Integrity Using RPM

Information

RPM has the capability of verifying installed packages by comparing the installed files against the file information stored in the package.

Rationale:

Verifying packages gives a system administrator the ability to detect if package files were changed, which could indicate that a valid binary was overwritten with a trojaned binary.

Solution

Address unexpected discrepancies identified in the audit step.

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, CSCv7|14.9

Plugin: Unix

Control ID: b02c7441f7d1c24ec9e24eedf1c81d4fce1f34c17c8e077c1b7b7293e8f82876