UCF STIG Viewer Logo

All system audit files must not have extended ACLs.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22369 GEN002710 SV-38748r1_rule ECTP-1 Medium
Description
If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.
STIG Date
AIX 5.3 SECURITY TECHNICAL IMPLEMENTATION GUIDE 2014-10-03

Details

Check Text ( C-37248r1_chk )
Procedure:
# grep -p bin: /etc/security/audit/config
Directories and files to search will be listed under the bin stanza.
#aclget /

Check if extended permissions are disabled. If extended permissions are not disabled, this is a finding.
Fix Text (F-32466r1_fix)
Remove the extended ACL from the system audit file(s) and disable extended permissions.

#acledit / and disable extended permissions