GEN002717 - System audit tool executables must have mode 0750 or less permissive - '/usr/sbin/auditstream' - suid

Information

To prevent unauthorized access or manipulation of system audit logs, the tools for manipulating those logs must be protected.

Solution

Many audit tools have SUID bit set. Before changing permissions on system audit tool executables, check the file permissions for SUID bits. Change the mode of system audit tool executables to 0750.
#chmod 0750 or 4750 <system audit tool executable>
Document all changes made.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CAT|III, CCI|CCI-001493, Rule-ID|SV-38778r1_rule, STIG-ID|GEN002717, Vuln-ID|V-22372

Plugin: Unix

Control ID: 20b836e107e1b0a29198f9d11c26efc1e85e0e3aa7fdfa78871ec0ce8ece225d