GEN000140-3 - A file integrity baseline including cryptographic hashes must be maintained. - '/etc/aide.conf exists'

Information

A file integrity baseline is a collection of file metadata that is to evaluate the integrity of the system. A minimal baseline must contain metadata for all device files, setuid files, setgid files, system libraries, system binaries, and system configuration files. The minimal metadata must consist of the mode, owner, group owner, and modification times. For regular files, metadata must also include file size and a cryptographic hash of the file's contents.

Solution

Regularly rebuild the integrity baseline, including cryptographic hashes, for the system to be consistent with the latest approved system configuration.

Procedure:
After an approved modification to the system configuration has been made perform:

# aide -u
This will update the database.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2, CAT|II, CCI|CCI-000293, Group-ID|V-27251, Rule-ID|SV-34550r2_rule, STIG-ID|GEN000140-3, Vuln-ID|V-27251

Plugin: Unix

Control ID: b780de5dedac495319a4f488281472763ac1049920012580b4ff38526c0ab2a3