[Forgot Password]
Login  Register Subscribe

25354

 
 

132805

 
 

141151

 
 

909

 
 

114115

 
 

156

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-90649-5

Platform: rhel7,centos7Date: (C)2017-06-29   (M)2020-02-19



Record Events that Modify the System's Network Environment If the 'auditd' daemon is configured to use the 'augenrules' program to read audit rules during daemon startup (the default), add the following lines to a file with suffix '.rules' in the directory '/etc/audit/rules.d', setting ARCH to either b32 or b64 as appropriate for your system: -a always,exit -F arch=ARCH -S sethostname -S setdomainname -k audit_rules_networkconfig_modification -w /etc/issue -p wa -k audit_rules_networkconfig_modification -w /etc/issue.net -p wa -k audit_rules_networkconfig_modification -w /etc/hosts -p wa -k audit_rules_networkconfig_modification -w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification If the 'auditd' daemon is configured to use the 'auditctl' utility to read audit rules during daemon startup, add the following lines to '/etc/audit/audit.rules' file, setting ARCH to either b32 or b64 as appropriate for your system: -a always,exit -F arch=ARCH -S sethostname -S setdomainname -k audit_rules_networkconfig_modification -w /etc/issue -p wa -k audit_rules_networkconfig_modification -w /etc/issue.net -p wa -k audit_rules_networkconfig_modification -w /etc/hosts -p wa -k audit_rules_networkconfig_modification -w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification


Parameter:


Technical Mechanism: The network environment should not be modified by anything other than administrator action. Any change to network parameters should be audited. Fix: No Remediation Info

References:

Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:30340
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:31063


OVAL    2
oval:org.secpod.oval:def:30340
oval:org.secpod.oval:def:31063
XCCDF    2
xccdf_org.secpod_benchmark_general_RHEL_7
xccdf_org.secpod_benchmark_general_CENTOS_7

© SecPod Technologies