The Photon operating system must enable the auditd service.
DISA Rule
SV-258808r1015938_rule
Vulnerability Number
V-258808
Group Title
SRG-OS-000039-GPOS-00017
Rule Version
PHTN-40-000016
Severity
CAT II
CCI(s)
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-001744 - Implement organization-defined security responses automatically if baseline configurations are changed in an unauthorized manner.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-002699 - Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
Weight
10
Fix Recommendation
At the command line, run the following commands:
# systemctl enable auditd
# systemctl start auditd
Check Contents
At the command line, run the following command to verify auditd is enabled and running:
# systemctl status auditd
If the service is not enabled and running, this is a finding.
Vulnerability Number
V-258808
Documentable
False
Rule Version
PHTN-40-000016
Severity Override Guidance
At the command line, run the following command to verify auditd is enabled and running:
# systemctl status auditd
If the service is not enabled and running, this is a finding.
Check Content Reference
M
Target Key
5569