5.2.3.3 Ensure use of privileged commands are collected

Information

Monitor privileged programs, those that have the setuid and/or setgid bit set on execution, to determine if unprivileged users are running these commands.

Execution of privileged commands by non-privileged users could be an indication of someone trying to gain unauthorized access to the system.

Solution

Edit the file /etc/security/audit_control, with the relevant rules to monitor events that modify files.

Modify the flags directive to match the following:

flags:pc

These flags should be added if there were other flags previously configured rather than replacing the entire line.

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-7, 800-53|AU-12, CSCv7|6.2

Plugin: Unix

Control ID: f604f8a4e3395debf8180488739caa9df522059d1eece90076bddf126aef4f1a