RHEL-06-000385 - Audit log directories must have mode 0755 or less permissive.

Information

If users can delete audit logs, audit trails can be modified or destroyed.

Solution

Change the mode of the audit log directories with the following command:

# chmod go-w [audit_directory]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9, CAT|II, CCI|CCI-000164, Rule-ID|SV-218086r603264_rule, STIG-ID|RHEL-06-000385, STIG-Legacy|SV-50294, STIG-Legacy|V-38493, Vuln-ID|V-218086

Plugin: Unix

Control ID: 8267e6cfc7d5486a423bae5b6a9e0e2f3ce60a41f4ba1160dd3e006ea0bcf3ff