Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-51171 | OL6-00-000183 | SV-65381r1_rule | Low |
Description |
---|
The system's mandatory access policy (SELinux) should not be arbitrarily changed by anything other than administrator action. All changes to MAC policy should be audited. |
STIG | Date |
---|---|
Oracle Linux 6 Security Technical Implementation Guide | 2014-06-12 |
Check Text ( C-53575r1_chk ) |
---|
To determine if the system is configured to audit changes to its SELinux configuration files, run the following command: # auditctl -l | grep "dir=/etc/selinux" If the system is configured to watch for changes to its SELinux configuration, a line should be returned (including "perm=wa" indicating permissions that are watched). If the system is not configured to audit attempts to change the MAC policy, this is a finding. |
Fix Text (F-55979r1_fix) |
---|
Add the following to "/etc/audit/audit.rules": -w /etc/selinux/ -p wa -k MAC-policy |