The SUSE operating system must have the auditing package installed.
DISA Rule
SV-234964r1009639_rule
Vulnerability Number
V-234964
Group Title
SRG-OS-000337-GPOS-00129
Rule Version
SLES-15-030650
Severity
CAT II
CCI(s)
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001875 - Provide an audit reduction capability that supports on-demand audit review and analysis.
- CCI-001877 - Provide an audit reduction capability that supports after-the-fact investigations of incidents.
- CCI-001878 - Provide a report generation capability that supports on-demand audit review and analysis.
- CCI-001879 - Provide a report generation capability that supports on-demand reporting requirements.
- CCI-001880 - Provide a report generation capability that supports after-the-fact investigations of security incidents.
- CCI-001881 - Provide an audit reduction capability that does not alter original content or time ordering of audit records.
- CCI-001882 - Provide a report generation capability that does not alter original content or time ordering of audit records.
- CCI-001889 - Record time stamps for audit records that meet organization-defined granularity of time measurement.
- CCI-001914 - Provide the capability for organization-defined individuals or roles to change the logging to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds.
Weight
10
Fix Recommendation
The SUSE operating system auditd package must be installed on the system. If it is not installed, use the following command to install it:
> sudo zypper in audit
Check Contents
Verify the SUSE operating system auditing package is installed.
Check that the "audit" package is installed by performing the following command:
> zypper info audit | grep Installed
i | audit | User Space Tools for 2.6 Kernel Auditing
If the package "audit" is not installed on the system, then this is a finding.
Vulnerability Number
V-234964
Documentable
False
Rule Version
SLES-15-030650
Severity Override Guidance
Verify the SUSE operating system auditing package is installed.
Check that the "audit" package is installed by performing the following command:
> zypper info audit | grep Installed
i | audit | User Space Tools for 2.6 Kernel Auditing
If the package "audit" is not installed on the system, then this is a finding.
Check Content Reference
M
Target Key
5274