ALMA-09-056890 - AlmaLinux OS 9 must use cryptographic mechanisms to protect the integrity of audit tools.

Information

Protecting the integrity of the tools used for auditing purposes is a critical step toward ensuring the integrity of audit information. Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity.

Satisfies: SRG-OS-000278-GPOS-00108, SRG-OS-000257-GPOS-00098

Solution

Add or update the following lines to "/etc/aide.conf", to protect the integrity of the audit tools:

/usr/sbin/auditctl p+i+n+u+g+s+b+acl+xattrs+sha512
/usr/sbin/auditd p+i+n+u+g+s+b+acl+xattrs+sha512
/usr/sbin/ausearch p+i+n+u+g+s+b+acl+xattrs+sha512
/usr/sbin/aureport p+i+n+u+g+s+b+acl+xattrs+sha512
/usr/sbin/autrace p+i+n+u+g+s+b+acl+xattrs+sha512
/usr/sbin/augenrules p+i+n+u+g+s+b+acl+xattrs+sha512

See Also

https://workbench.cisecurity.org/benchmarks/0

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, 800-53|AU-9(3), CAT|II, CCI|CCI-001494, CCI|CCI-001496, Rule-ID|SV-269545r1050428_rule, STIG-ID|ALMA-09-056890, Vuln-ID|V-269545

Plugin: Unix

Control ID: c36309898a5ac2fdc5752b8daf5f93bc0fe2a1d55d493aee70a8e7e826462a30