GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents

Information

File integrity tools often use cryptographic hashes for verifying file contents have not been altered. These hashes must be FIPS 140-2 approved.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

If using AIDE, edit the configuration and add the sha512 option for all monitored files and directories.

If using a different file integrity tool, configure FIPS 140-2 approved cryptographic hashes per the tool's documentation.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

References: CAT|III, CCI|CCI-001297, Rule-ID|SV-35194r1_rule, STIG-ID|GEN006575, Vuln-ID|V-22509

Plugin: Unix

Control ID: 8305b7d5a47eaaf80fe56479ea4844dae02f872508b44c097e994f9cde7d5434