Cis Ubuntu1804 V220 4 3 3

Ensure sudo log file exists

cyberstrikeus Updated

File contents

CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 4.3.3

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

sudo can use a custom log file.

Rationale

A sudo log file simplifies auditing of sudo commands.

Audit Procedure

Command Line

Run the following command to verify that sudo has a custom log file configured:

grep -rPsi '^\h*Defaults\h+([^#]+,\h*)?logfile\h*=\h*(")?[\/\w]+(")?' /etc/sudoers /etc/sudoers.d/

Expected Result

Defaults logfile="/var/log/sudo.log"

Remediation

Command Line

Edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo and add the following line:

Defaults logfile="/var/log/sudo.log"

References

  1. NIST SP 800-53 Rev. 5: AU-3, AU-12

CIS Controls

v8 - 8.5 Collect Detailed Audit Logs - Configure detailed audit logging for enterprise assets containing sensitive data.

v7 - 6.3 Enable Detailed Logging.

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Assessment Status

Automated

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-18-04-lts-benchmark-v2/cis-ubuntu1804-v220-4-3-3 commit 067394b36a

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1804-v220-4-3-3