<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://secscan.acron.pl/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://secscan.acron.pl/feed.php">
        <title>SecScan centos7:4:1</title>
        <description></description>
        <link>https://secscan.acron.pl/</link>
        <image rdf:resource="https://secscan.acron.pl/lib/tpl/bootstrap3/images/favicon.ico" />
       <dc:date>2026-08-31T09:45:45+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/1?rev=1494076662&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/2?rev=1493913340&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/3?rev=1493913386&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/4?rev=1493913416&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/5?rev=1493913440&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/6?rev=1493913740&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/7?rev=1493913922&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/8?rev=1493914052&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/9?rev=1493914096&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/10?rev=1493914290&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/11?rev=1493914322&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/12?rev=1493914352&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/13?rev=1493914380&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/14?rev=1493914404&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/15?rev=1493914470&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/16?rev=1493914496&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/17?rev=1493914522&amp;do=diff"/>
                <rdf:li rdf:resource="https://secscan.acron.pl/centos7/4/1/18?rev=1493914540&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://secscan.acron.pl/lib/tpl/bootstrap3/images/favicon.ico">
        <title>SecScan</title>
        <link>https://secscan.acron.pl/</link>
        <url>https://secscan.acron.pl/lib/tpl/bootstrap3/images/favicon.ico</url>
    </image>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/1?rev=1494076662&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-06T15:17:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.1 Configure Data Retention</title>
        <link>https://secscan.acron.pl/centos7/4/1/1?rev=1494076662&amp;do=diff</link>
        <description>4.1.1 Configure Data Retention

List of content
1 index


Description

When auditing, it is important to carefully configure the storage requirements for audit logs. By default, auditd will max out the log files at 5MB and retain only 4 copies of them. Older versions will be deleted. It is possible on a system that the 20 MBs of audit logs may fill up the system causing loss of audit data. While the recommendations here provide guidance, check your site policy for audit storage requirements.</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/2?rev=1493913340&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T17:55:40+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.2 Ensure auditd service is enabled (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/2?rev=1493913340&amp;do=diff</link>
        <description>4.1.2 Ensure auditd service is enabled (Scored)

Profile Applicability

Description

Turn on the auditd daemon to record system events.

Rationale

The capturing of system events provides system administrators with information to allow them to determine if unauthorized access to their system is occurring.</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/3?rev=1493913386&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T17:56:26+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.3 Ensure auditing for processes that start prior to auditd is enabled (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/3?rev=1493913386&amp;do=diff</link>
        <description>4.1.3 Ensure auditing for processes that start prior to auditd is enabled (Scored)

Profile Applicability

Description

Configure grub so that processes that are capable of being audited can be audited even if they start up prior to auditd startup.

Rationale</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/4?rev=1493913416&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T17:56:56+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.4 Ensure events that modify date and time information are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/4?rev=1493913416&amp;do=diff</link>
        <description>4.1.4 Ensure events that modify date and time information are collected (Scored)

Profile Applicability

Description

Capture events where the system date and/or time has been modified. The parameters in this section are set to determine if the adjtimex</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/5?rev=1493913440&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T17:57:20+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.5 Ensure events that modify user/group information are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/5?rev=1493913440&amp;do=diff</link>
        <description>4.1.5 Ensure events that modify user/group information are collected (Scored)

Profile Applicability

Description

Record events affecting the group, passwd (user IDs), shadow and gshadow (passwords) or /etc/security/opasswd (old passwords, based on remember parameter in the PAM configuration) files. The parameters in this section will watch the files to see if they have been opened for write or have had attribute changes (e.g. permissions) and tag them with the identifier</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/6?rev=1493913740&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:02:20+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.6 Ensure events that modify the system's network environment are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/6?rev=1493913740&amp;do=diff</link>
        <description>4.1.6 Ensure events that modify the system's network environment are collected (Scored)

Profile Applicability

Description

Record changes to network environment files or system calls. The below parameters monitor the sethostname (set the systems host name) or setdomainname (set the systems domainname) system calls, and write an audit event on system call exit. The other parameters monitor the</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/7?rev=1493913922&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:05:22+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/7?rev=1493913922&amp;do=diff</link>
        <description>4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected (Scored)

Profile Applicability

Description

Monitor SELinux mandatory access controls. The parameters below monitor any write access (potential additional, deletion or modification of files in the directory) or attribute changes to the /etc/selinux or directory.</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/8?rev=1493914052&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:07:32+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.8 Ensure login and logout events are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/8?rev=1493914052&amp;do=diff</link>
        <description>4.1.8 Ensure login and logout events are collected (Scored)

Profile Applicability

Description

Monitor login and logout events. The parameters below track changes to files associated with login/logout events. The file /var/log/lastlog maintain records of the last time a user successfully logged in. The</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/9?rev=1493914096&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:08:16+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.9 Ensure session initiation information is collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/9?rev=1493914096&amp;do=diff</link>
        <description>4.1.9 Ensure session initiation information is collected (Scored)

Profile Applicability

Description

Monitor session initiation events. The parameters in this section track changes to the files associated with session events. The file /var/run/utmp</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/10?rev=1493914290&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:11:30+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.10 Ensure discretionary access control permission modification events are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/10?rev=1493914290&amp;do=diff</link>
        <description>4.1.10 Ensure discretionary access control permission modification events are collected (Scored)

Profile Applicability

Description

Monitor changes to file permissions, attributes, ownership and group. The parameters in this section track changes for system calls that affect file permissions and attributes. The</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/11?rev=1493914322&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:12:02+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.11 Ensure unsuccessful unauthorized file access attempts are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/11?rev=1493914322&amp;do=diff</link>
        <description>4.1.11 Ensure unsuccessful unauthorized file access attempts are collected (Scored)

Profile Applicability

Description

Monitor for unsuccessful attempts to access files. The parameters below are associated with system calls that control creation (creat</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/12?rev=1493914352&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:12:32+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.12 Ensure use of privileged commands is collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/12?rev=1493914352&amp;do=diff</link>
        <description>4.1.12 Ensure use of privileged commands is collected (Scored)

Profile Applicability

Description

Monitor privileged programs (those that have the setuid and/or setgid bit set on execution) to determine if unprivileged users are running these commands.</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/13?rev=1493914380&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:13:00+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.13 Ensure successful file system mounts are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/13?rev=1493914380&amp;do=diff</link>
        <description>4.1.13 Ensure successful file system mounts are collected (Scored)

Profile Applicability

Description

Monitor the use of the mount system call. The mount (and umount) system call controls the mounting and unmounting of file systems. The parameters below configure the system to create an audit record when the mount system call is used by a non-privileged user</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/14?rev=1493914404&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:13:24+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.14 Ensure file deletion events by users are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/14?rev=1493914404&amp;do=diff</link>
        <description>4.1.14 Ensure file deletion events by users are collected (Scored)

Profile Applicability

Description

Monitor the use of system calls associated with the deletion or renaming of files and file attributes. This configuration statement sets up monitoring for the</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/15?rev=1493914470&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:14:30+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.15 Ensure changes to system administration scope (sudoers) is collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/15?rev=1493914470&amp;do=diff</link>
        <description>4.1.15 Ensure changes to system administration scope (sudoers) is collected (Scored)

Profile Applicability

Description

Monitor scope changes for system administrations. If the system has been properly configured to force system administrators to log in as themselves first and then use the</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/16?rev=1493914496&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:14:56+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.16 Ensure system administrator actions (sudolog) are collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/16?rev=1493914496&amp;do=diff</link>
        <description>4.1.16 Ensure system administrator actions (sudolog) are collected (Scored)

Profile Applicability

Description

Monitor the sudo log file. If the system has been properly configured to disable the use of the su command and force all administrators to have to log in first and then use</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/17?rev=1493914522&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:15:22+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.17 Ensure kernel module loading and unloading is collected (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/17?rev=1493914522&amp;do=diff</link>
        <description>4.1.17 Ensure kernel module loading and unloading is collected (Scored)

Profile Applicability

Description

Monitor the loading and unloading of kernel modules. The programs insmod (install a kernel module), rmmod (remove a kernel module), and modprobe</description>
    </item>
    <item rdf:about="https://secscan.acron.pl/centos7/4/1/18?rev=1493914540&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-05-04T18:15:40+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>4.1.18 Ensure the audit configuration is immutable (Scored)</title>
        <link>https://secscan.acron.pl/centos7/4/1/18?rev=1493914540&amp;do=diff</link>
        <description>4.1.18 Ensure the audit configuration is immutable (Scored)

Profile Applicability

Description

Set system audit so that audit rules cannot be modified with auditctl. Setting the flag -e 2 forces audit to be put in immutable mode. Audit changes can only be made on system reboot.</description>
    </item>
</rdf:RDF>
