RHEL 9 audit package must be installed.
DISA Rule
SV-258151r1045298_rule
Vulnerability Number
V-258151
Group Title
SRG-OS-000062-GPOS-00031
Rule Version
RHEL-09-653010
Severity
CAT II
CCI(s)
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000154 - Provide the capability to centrally review and analyze audit records from multiple components within the system.
- CCI-000158 - Provide the capability to process, sort, and search audit records for events of interest based on organization-defined audit fields within audit records.
- CCI-000159 - Use internal system clocks to generate time stamps for audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001875 - Provide an audit reduction capability that supports on-demand audit review and analysis.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
- CCI-001877 - Provide an audit reduction capability that supports after-the-fact investigations of incidents.
- CCI-001878 - Provide a report generation capability that supports on-demand audit review and analysis.
- CCI-001879 - Provide a report generation capability that supports on-demand reporting requirements.
- CCI-001880 - Provide a report generation capability that supports after-the-fact investigations of security incidents.
- CCI-001881 - Provide an audit reduction capability that does not alter original content or time ordering of audit records.
- CCI-001882 - Provide a report generation capability that does not alter original content or time ordering of audit records.
- CCI-001889 - Record time stamps for audit records that meet organization-defined granularity of time measurement.
- CCI-001914 - Provide the capability for organization-defined individuals or roles to change the logging to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds.
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
Weight
10
Fix Recommendation
Install the audit service package (if the audit service is not already installed) with the following command:
$ sudo dnf install audit
Check Contents
Verify that the RHEL 9 audit service package is installed.
Check that the audit service package is installed with the following command:
$ dnf list --installed audit
Example output:
audit-3.0.7-101.el9_0.2.x86_64
If the "audit" package is not installed, this is a finding.
Vulnerability Number
V-258151
Documentable
False
Rule Version
RHEL-09-653010
Severity Override Guidance
Verify that the RHEL 9 audit service package is installed.
Check that the audit service package is installed with the following command:
$ dnf list --installed audit
Example output:
audit-3.0.7-101.el9_0.2.x86_64
If the "audit" package is not installed, this is a finding.
Check Content Reference
M
Target Key
5551