[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50407-6

Platform: cpe:/o:apple:mac_os_14Date: (C)2024-04-23   (M)2024-04-23



/etc/security/audit_control must not contain Access Control Lists (ACLs). /etc/security/audit_control contains sensitive configuration data about the audit service. This rule ensures that the audit service is configured to be readable and writable only by system administrators in order to prevent normal users from manipulating audit logs. Audit: Verify the macOS system is configured without ACLs applied to audit_control with the following command: /bin/ls -le /etc/security/audit_control | /usr/bin/awk '{print $1}' | /usr/bin/grep -c ":" If the result is not "0", this is a finding. Remediation: Configure the macOS system without ACLs applied to audit_control with the following command: /bin/chmod -N /etc/security/audit_control NOTE:/etc/security/audit_control is deprecated and disabled in Mac OS 14, the files are not present in the system by default. If remediated in this particular case (File not present) rollback will not behave as expected.


Parameter:

[Yes/No]


Technical Mechanism:

Configure the macOS system without ACLs applied to audit_control with the following command: /bin/chmod -N /etc/security/audit_control

CCSS Severity:CCSS Metrics:
CCSS Score : 7.8Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99406


OVAL    1
oval:org.secpod.oval:def:99406
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_14

© SecPod Technologies