UCF STIG Viewer Logo

System audit logs must be owned by root.


Overview

Finding ID Version Rule ID IA Controls Severity
V-812 GEN002680 SV-27271r1_rule ECTP-1 Medium
Description
Failure to give ownership of system audit log files to root provides the designated owner and unauthorized users with the potential to access sensitive information.
STIG Date
SOLARIS 9 SPARC SECURITY TECHNICAL IMPLEMENTATION GUIDE 2015-10-01

Details

Check Text ( C-28369r1_chk )
Perform the following to determine the location of audit logs and then check the ownership.
# more /etc/security/audit_control
# ls -lLa
If any audit log file is not owned by root, this is a finding.
Fix Text (F-966r2_fix)
Change the ownership of the audit log file(s).

Procedure:
# chown root