Files
macos_security/rules/audit/audit_control_group_configure.yaml
2025-08-18 14:28:42 -04:00

62 lines
1.1 KiB
YAML

id: audit_control_group_configure
title: Configure Audit_Control Group to Wheel
discussion: |
/etc/security/audit_control _MUST_ have the group set to wheel.
check: |
/bin/ls -dn /etc/security/audit_control | /usr/bin/awk '{print $4}'
result:
integer: 0
fix: |
[source,bash]
----
/usr/bin/chgrp wheel /etc/security/audit_control
----
references:
cce:
- CCE-95107-9
cci:
- CCI-000162
- CCI-000163
- CCI-000164
- CCI-000171
- CCI-001493
- CCI-001494
- CCI-001495
800-53r5:
- AU-9
800-53r4:
- AU-9
srg:
- SRG-OS-000256-GPOS-00097
- SRG-OS-000057-GPOS-00027
- SRG-OS-000063-GPOS-00032
- SRG-OS-000059-GPOS-00029
- SRG-OS-000257-GPOS-00098
- SRG-OS-000258-GPOS-00099
- SRG-OS-000058-GPOS-00028
disa_stig:
- APPL-26-001110
800-171r3:
- 03.03.08
cis:
benchmark:
- 3.5 (level 1)
controls v8:
- 3.3
cmmc:
- AU.L2-3.3.8
macOS:
- '26.0'
tags:
- cis_lvl1
- cis_lvl2
- cisv8
- cnssi-1253_low
- cnssi-1253_high
- cmmc_lvl2
- stig
- cnssi-1253_moderate
severity: medium
mobileconfig: false
mobileconfig_info: