5.2.4.4 Ensure only authorized groups are assigned ownership of audit log files

Information

Audit log files contain information about the system and system activity.

Access to audit records can reveal system and configuration data to attackers, potentially compromising its confidentiality.

Solution

Run the following command to configure the audit log files to be owned by the audit group:

# chgrp audit /var/audit

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: fa03504abc68d883b06d550e4ef3a55497d7574934c4c20cab8def11fe5532c7