GEN006565 - The system package management tool must be used to verify system software periodically.

Information

Verification using the system package management tool can be used to determine that system software has not been tampered with. This requirement is not applicable to systems that do not use package management tools.

Solution

Add a job to the root crontab invoking the system package management tool to verify the integrity of installed packages.
# lppchk -c

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-6b., 800-53|SA-10(1), CAT|II, CCI|CCI-000366, CCI|CCI-000698, Rule-ID|SV-38958r1_rule, STIG-ID|GEN006565, Vuln-ID|V-22506

Plugin: Unix

Control ID: 98a2116f15bd4beb3f7fc032f1283c3a44da69a893553793cc2f33b1b81fcafb