STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Amazon Linux 2023 Security Technical Implementation Guide

V-274098

CAT II (Medium)

Amazon Linux 2023 must audit all uses of the init command.

Rule ID

SV-274098r1120282_rule

STIG

Amazon Linux 2023 Security Technical Implementation Guide

Version

V1R3

CCIs

CCI-000172

Discussion

Misuse of the init command may cause availability issues for the system.

Check Content

Verify Amazon Linux 2023 is configured to audit the execution of the "init" command with the following command:

$ sudo auditctl -l | grep init
-a always,exit -F path=/usr/sbin/init -F perm=x -F auid>=1000 -F auid!=unset -k privileged-init

If the command does not return a line, or the line is commented out, this is a finding.

Fix Text

Configure Amazon Linux 2023 so that the audit system generates an audit event for any successful/unsuccessful uses of the "init" command by adding or updating the following rule in the "/etc/audit/rules.d/audit.rules" file:

-a always,exit -F path=/usr/sbin/init -F perm=x -F auid>=1000 -F auid!=unset -k privileged-init

To load the rules to the kernel immediately, use the following command: 

$ sudo augenrules --load