Record Events that Modify the System's Mandatory Access Controls in usr/share
An XCCDF Rule
Description
If the auditd
daemon is configured to use the
augenrules
program to read audit rules during daemon startup (the
default), add the following line to a file with suffix .rules
in the
directory /etc/audit/rules.d
:
-w /usr/share/selinux/ -p wa -k MAC-policyIf the
auditd
daemon is configured to use the auditctl
utility to read audit rules during daemon startup, add the following line to
/etc/audit/audit.rules
file:
-w /usr/share/selinux/ -p wa -k MAC-policy
Rationale
The system's mandatory access policy (SELinux) should not be arbitrarily changed by anything other than administrator action. All changes to MAC policy should be audited.
- ID
- xccdf_org.ssgproject.content_rule_audit_rules_mac_modification_usr_share
- Severity
- Medium
- References
- Updated