8.3.2 Implement Periodic Execution of File Integrity

Information

Implement periodic file checking, in compliance with site policy.

*Rationale*

Periodic file checking allows the system administrator to determine on a regular basis if
critical files have been changed in an unauthorized fashion.

Solution

Execute the following command-

# crontab -u root -eAdd the following line to the crontab-0 5 * * * /usr/sbin/aide --check

Note- The checking in this instance occurs every day at 5am. Alter the frequency and time
of the checks in compliance with site policy.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1)

Plugin: Unix

Control ID: a2adfdf6ea45bc1beb57648bf22b1f6050eb87c73c2ed37380c4a2e11ac3cdce