GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents.

Information

File integrity tools often use cryptographic hashes for verifying that file contents have not been altered. These hashes must be FIPS 140-2 approved.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

If using AIDE, edit the configuration and add the sha256 or sha512 option for all monitored files and directories.
If using a different file integrity tool, configure FIPS 140-2 approved cryptographic hashes per the tool's documentation.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7, CAT|III, CCI|CCI-001297, Rule-ID|SV-26861r1_rule, STIG-ID|GEN006575, Vuln-ID|V-22509

Plugin: Unix

Control ID: a7ed38340c1dc64327367b9f32e49270a843a7f2b0bf33a6f26dc7f6b17d24d6