STIGUI
V-282355CAT II — Medium severitySV-282355r1200045_rule

TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.

Rule version TOSS-05-000454 · STIG v1 · 2026-08-20

Discussion

In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications must be investigated for legitimacy.

Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000466-GPOS-00210, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000476-GPOS-00221

Check

Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group" using the following command:

$ sudo auditctl -l | egrep '(/etc/group)'  

-w /etc/group -p wa -k identity

If the command does not return a line or the line is commented out, this is a finding.

Fix

Configure TOSS 5 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group".

Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":

-w /etc/group -p wa -k identity

Restart the audit daemon for the changes to take effect.

Identifiers

Group ID
V-282355
Group title
SRG-OS-000004-GPOS-00004
Rule ID
SV-282355r1200045_rule
Check ID
C-86916r1200043_chk
Fix ID
F-86821r1200044_fix