6.2.3.4 Ensure rsyslog log file creation mode is configured

Information

The $FileCreateMode parameter allows to specify the creation mode with which rsyslogd creates new files.

It is important to ensure that log files have the correct permissions to ensure that sensitive data is archived and protected.

Solution

Edit either /etc/rsyslog.conf or a dedicated .conf file in /etc/rsyslog.d/ and set $FileCreateMode to 0640 or more restrictive:

$FileCreateMode 0640

Reload the service:

# systemctl reload-or-restart rsyslog

See Also

https://workbench.cisecurity.org/benchmarks/21369

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|MP-2, CSCv7|5.1, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: 2495dbf3afbcaf8dc5d4700a770fbee1516dba1e6bf2f0903630623e5009e181