8.1.7 Record Events That Modify the System's Mandatory Access Controls

Information

Monitor SELinux mandatory access controls. The parameters below monitor any write
access (potential additional, deletion or modification of files in the directory) or attribute
changes to the /etc/selinux directory.

*Rationale*

Changes to files in this directory could indicate that an unauthorized user is attempting to
modify access controls and change security contexts, leading to a compromise of the
system.

Solution

Add the following lines to the /etc/audit/audit.rules file.Add the following lines to /etc/audit/audit.rules
-w /etc/selinux/ -p wa -k MAC-policy
# Execute the following command to restart auditd
# pkill -P 1-HUP auditd

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: a3ae396a19e6cf8537b3063a2703e93c6df59413a96a442072af44e6a53a0037