RHEL-06-000183 - The audit system must be configured to audit modifications to the systems Mandatory Access Control (MAC) configuration (SELinux).

Information

The system's mandatory access policy (SELinux) should not be arbitrarily changed by anything other than administrator action. All changes to MAC policy should be audited.

Solution

Add the following to '/etc/audit/audit.rules':

-w /etc/selinux/ -p wa -k MAC-policy

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-217961r603264_rule, STIG-ID|RHEL-06-000183, STIG-Legacy|SV-50342, STIG-Legacy|V-38541, Vuln-ID|V-217961

Plugin: Unix

Control ID: d4bb47c58511608f806087ce18b32a586417041515c7a1779618830430d2626b