GEN002710 M6 - All system audit files must not have extended ACLs - '/var/audit/*'

Information

If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -N </var/audit/ file with extended ACL>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-3(4), 800-53|AU-9(4), CAT|II, CCI|CCI-000163, Rule-ID|SV-38102r1_rule, STIG-ID|GEN002710-M6, Vuln-ID|V-22369

Plugin: Unix

Control ID: a7e790cbd5b7d690b08fae5cc064b3cf4cff5346b5c1d88e80b3047f638d2621