UCF STIG Viewer Logo

All system audit files must not have extended ACLs.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22369 GEN002710 SV-26016r1_rule ECTP-1 Medium
Description
If a user can write to the audit logs, then audit trails can be modified or destroyed and system intrusion may not be detected.
STIG Date
UNIX SRG 2013-03-26

Details

Check Text ( C-29200r1_chk )
Determine if system audit files have an extended ACL. If any do, this is a finding.
Fix Text (F-26222r1_fix)
Remove the extended ACL from the system audit file(s).