4.1.2 Ensure permissions on journal files are configured

Information

The journal is stored in /var/log/journal, and contains logged information from all services on the system.

Rationale:

It is important to ensure that log files have the correct permissions to ensure that sensitive data is archived and protected.

Solution

Run the following commands to set permissions on all existing log files:

# find /var/log/journal -type f -perm /g+wx,o+rwx -exec chmod g-wx,o-rwx "{}" +

See Also

https://workbench.cisecurity.org/benchmarks/6709

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: 09ca132e48b7736557e6f576152507de4722532ccbab6091f6c8cf3845bc6578