GEN001260 M6 - System log files must have mode 644 or less permissive - '/var/log'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If the system log files are not protected, unauthorized users could change the logged data, eliminating its forensic value.

Solution

Open a terminal session and enter the following command to change the mode of the system log file(s).

chmod 644 <path/to/system log file>

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-001314, CSCv6|3.1, Rule-ID|SV-37890r1_rule, STIG-ID|GEN001260-M6, Vuln-ID|V-787

Plugin: Unix

Control ID: 38c3ddd1d2999b02df632434b92dacf5960d14b4e479f68875a5921372ca735f