Logs containing auditing information should be secured at the directory level.

Information

Only root or web administrators must be able to read and write to log files.

Solution

1. The HTTP server configuration file is located at <IBM Http Installation directory>/logs
2. Ensure that only the administrators and no unauthorized users have permissions on the logs directory.

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CSCv6|3.1

Plugin: Unix

Control ID: 3d609a9d00777eec215953212df0a49b1d2657544a61f18edc9b8e1a0029fbbb