GEN002710 - All system audit files must not have extended ACLs.

Information

If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.

Solution

Remove the extended ACL from the system audit file(s).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CAT|II, CCI|CCI-000163, Rule-ID|SV-218380r603259_rule, STIG-ID|GEN002710, STIG-Legacy|SV-63885, STIG-Legacy|V-22369, Vuln-ID|V-218380

Plugin: Unix

Control ID: 438b2c1c43cb792c615cfebe273b9fc0f8dc15bd643247b15522e55bdc0fedf6