8.3.2 Implement Periodic Execution of File Integrity

Information

Implement periodic file checking, in compliance with site policy. Periodic file checking allows the system administrator to determine on a regular basis if critical files have been changed in an unauthorized fashion.

Solution

Execute the following command- # crontab -u root -e Add the following line to the crontab- 0 5 * * * /usr/sbin/aide --check Note- The checking in this instance occurs every day at 5am. Alter the frequency and time of the checks in compliance with site policy.

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1)

Plugin: Unix

Control ID: 93e10e90d2e4c5e883bcca686b5cc9617446c6e7efcacbe965ed166dc568740a