4.3 Enable Auditing of File Metadata Modification Events - AUE_FCHMOD : cis

Information

NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.

Solution

To enforce this setting, edit the /etc/security/audit_event file and add the cis audit class to the following audit events:
AUE_CHMOD
AUE_CHOWN
AUE_FCHOWN
AUE_FCHMOD
AUE_LCHOWN
AUE_ACLSET
AUE_FACLSET

See Also

https://workbench.cisecurity.org/files/612

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 53c1ad62ff6cf7b4329d696f4aae7658e2670da9aac983d04096fd80e5964223