STIGUI
V-282358CAT II — Medium severitySV-282358r1200054_rule

TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.

Rule version TOSS-05-000457 · STIG v1 · 2026-08-20

Discussion

In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy.

Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000466-GPOS-00210, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000476-GPOS-00221

Check

Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd" using the following command:

$ sudo auditctl -l | egrep '(/etc/passwd)' 

-w /etc/passwd -p wa -k identity

If the command does not return a line or the line is commented out, this is a finding.

Fix

Configure TOSS 5 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd".

Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":

-w /etc/passwd -p wa -k identity

Restart the audit daemon for the changes to take effect.

Identifiers

Group ID
V-282358
Group title
SRG-OS-000004-GPOS-00004
Rule ID
SV-282358r1200054_rule
Check ID
C-86919r1200052_chk
Fix ID
F-86824r1200053_fix