GEN002710 - All system audit files must not have extended ACLs

Information

If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

As root, remove the ACL.
# chacl -z <audit directory>
# chacl -z <audit file>

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000163, Rule-ID|SV-38355r2_rule, STIG-ID|GEN002710, Vuln-ID|V-22369

Plugin: Unix

Control ID: f1591cec4a6ea6e7cad31fbc576753fb707ca16dbb157aa2c369ccfaaa45622d