GEN000140-2 - A file integrity baseline including cryptographic hashes must be created - '/etc/aide.conf must exist'

Information

A file integrity baseline is a collection of file metadata which is to evaluate the integrity of the system. A minimal baseline must contain metadata for all device files, setuid files, setgid files, system libraries, system binaries, and system configuration files. The minimal metadata must consist of the mode, owner, group owner, and modification times. For regular files, metadata must also include file size and a cryptographic hash of the file's contents.

Solution

Use AIDE to create a file integrity baseline, including cryptographic hashes, for the system.

Configure the /etc/aide.conf file to ensure some form of cryptographic hash (e.g., md5, rmd160, sha256) is used for files. In the default /etc/aide.conf the 'NORMAL' or 'LSPP' rules which are used for virtually all files DO include some form of cryptographic hash.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2, 800-53|CM-3(5), CAT|II, CCI|CCI-000293, CCI|CCI-001744, Rule-ID|SV-218190r603259_rule, STIG-ID|GEN000140-2, STIG-Legacy|SV-63101, STIG-Legacy|V-27250, Vuln-ID|V-218190

Plugin: Unix

Control ID: 2da8b450dff6409664ea099dd5715316617f7cd2f003a2ea3a4e2b6715a1a9ab