Files
macos_security/rules/audit/audit_folders_mode_configure.yaml
2025-08-18 14:28:42 -04:00

69 lines
1.5 KiB
YAML

id: audit_folders_mode_configure
title: Configure Audit Log Folders to Mode 700 or Less Permissive
discussion: |
The audit log folder _MUST_ be configured to mode 700 or less permissive so that only the root user is able to read, write, and execute changes to folders.
Because audit logs contain sensitive data about the system and users, the audit service _MUST_ be configured to mode 700 or less permissive; thereby preventing normal users from reading, modifying or deleting audit logs.
check: |
/usr/bin/stat -f %A $(/usr/bin/grep '^dir' /etc/security/audit_control | /usr/bin/awk -F: '{print $2}')
result:
integer: 700
fix: |
[source,bash]
----
/bin/chmod 700 /var/audit
----
references:
cce:
- CCE-95126-9
cci:
- CCI-000162
- CCI-000163
- CCI-000164
- CCI-001493
- CCI-001494
- CCI-001495
800-53r5:
- AU-9
800-53r4:
- AU-9
srg:
- SRG-OS-000256-GPOS-00097
- SRG-OS-000057-GPOS-00027
- SRG-OS-000059-GPOS-00029
- SRG-OS-000257-GPOS-00098
- SRG-OS-000258-GPOS-00099
- SRG-OS-000058-GPOS-00028
disa_stig:
- APPL-26-001017
800-171r3:
- 03.03.08
cis:
benchmark:
- 3.5 (level 1)
controls v8:
- 3.3
cmmc:
- AU.L2-3.3.8
macOS:
- '26.0'
tags:
- 800-53r5_low
- 800-53r5_moderate
- 800-53r5_high
- 800-53r4_low
- 800-53r4_moderate
- 800-53r4_high
- 800-171
- cis_lvl1
- cis_lvl2
- cisv8
- cnssi-1253_low
- cnssi-1253_high
- cmmc_lvl2
- stig
- cnssi-1253_moderate
severity: medium
mobileconfig: false
mobileconfig_info: