PHTN-67-000053 - The Photon operating system package files must not be modified.

Information

Protecting the integrity of the tools used for auditing purposes is a critical step toward ensuring the integrity of audit information. Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. Without confidence in the integrity of the auditing system and tools, the information it provides cannot be trusted.

Solution

If the audit system binaries have been altered, the system must be taken offline and the ISSM must be notified immediately.

Reinstalling the audit tools is not supported.

The appliance should be restored from a backup or a snapshot or redeployed once the root cause is remediated.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(3), CAT|II, CCI|CCI-001496, Rule-ID|SV-239124r877393_rule, STIG-ID|PHTN-67-000053, Vuln-ID|V-239124

Plugin: Unix

Control ID: 910757406ecd8f22d79d1b102821fb3c143606ee74bf59d69af064a81de71f49