8.3.2 Implement Periodic Execution of File Integrity

Information

Implement periodic file checking, in compliance with site policy.

*Rationale*

Periodic file checking allows the system administrator to determine on a regular basis if
critical files have been changed in an unauthorized fashion.

Solution

Execute the following command-

# crontab -u root -eAdd the following line to the crontab-0 5 * * * /usr/sbin/aide --check

Note- The checking in this instance occurs every day at 5am. Alter the frequency and time
of the checks in compliance with site policy.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1)

Plugin: Unix

Control ID: 9177b3cda2c99848c037ca24d68372f8ac0700e83f09b7e18caa763823ac9c96