1.2.7 Verify Package Integrity Using RPM

Information

RPM has the capability of verifying installed packages by comparing the installed files against the file information stored in the package.

Rationale:

Verifying packages gives a system administrator the ability to detect if package files were changed, which could indicate that a valid binary was overwritten with a trojaned binary.

Solution

Address unexpected discrepancies identified in the audit step.

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, CSCv7|14.9

Plugin: Unix

Control ID: 0fe7f968848717d12c127d87eb4e8c9ae1d7e17c68442483c1bb3b5c41c250f5