Information
Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confidentiality.
Audit information includes all information (e.g., audit records, audit settings, audit reports) needed to successfully audit operating system activity.
Satisfies: SRG-OS-000057-GPOS-00027, SRG-OS-000058-GPOS-00028, SRG-OS-000059-GPOS-00029, SRG-OS-000206-GPOS-00084
Solution
Configure Amazon Linux 2023 so that the audit logs have a mode of "0600".
Replace "[audit_log_file]" to the correct audit log path, by default this location is "/var/log/audit/audit.log".
$ sudo chmod 0600 /var/log/audit/[audit_log_file]
Check the group that owns the system audit logs:
$ sudo grep -iw log_group /etc/audit/auditd.conf
If the log_group is not defined or it is set to root, configure the permissions as follows:
$ sudo chmod 0640 $log_file
$ sudo chmod 0440 $log_file.*
Otherwise, configure the permissions as follows:
$ sudo chmod 0600 $log_file
$ sudo chmod 0400 $log_file.*
Item Details
Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY
References: 800-53|AU-9, 800-53|SI-11b., CAT|II, CCI|CCI-000162, CCI|CCI-000163, CCI|CCI-000164, CCI|CCI-001314, Rule-ID|SV-274110r1120318_rule, STIG-ID|AZLX-23-002235, Vuln-ID|V-274110
Control ID: b8a1abc18f526244a856fcbed6bd433f94cc0f9c99d81b71406a2e08d69badf7