GEN002718 M6 - System audit tool executables must not have extended ACLs - '/usr/sbin/auditd'

Information

To prevent unauthorized access or manipulation of system audit logs, the tools for manipulating those logs must be protected.

Solution

Open a terminal session and use the following command to remove the extended ACLs.

chmod -N <audit file with extended ACL>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-3(4), 800-53|AU-9(4), CAT|III, CCI|CCI-001493, Rule-ID|SV-38103r1_rule, STIG-ID|GEN002718-M6, Vuln-ID|V-22373

Plugin: Unix

Control ID: aea55f36769e5b57e7e96fef7ef18c6b411e7b505fa7796f7400a17c5e0463cd