The Photon operating system must have the auditd service running.
DISA Rule
SV-256490r958422_rule
Vulnerability Number
V-256490
Group Title
SRG-OS-000042-GPOS-00021
Rule Version
PHTN-30-000013
Severity
CAT II
CCI(s)
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-001744 - Implement organization-defined security responses automatically if baseline configurations are changed in an unauthorized manner.
- CCI-002696 - Verify correct operation of organization-defined security functions.
- CCI-002699 - Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
Weight
10
Fix Recommendation
At the command line, run the following commands:
# systemctl enable auditd
# systemctl start auditd
Check Contents
At the command line, run the following command:
# systemctl status auditd
If the service is not running, this is a finding.
Vulnerability Number
V-256490
Documentable
False
Rule Version
PHTN-30-000013
Severity Override Guidance
At the command line, run the following command:
# systemctl status auditd
If the service is not running, this is a finding.
Check Content Reference
M
Target Key
5520