SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
DISA Rule
SV-261411r996646_rule
Vulnerability Number
V-261411
Group Title
SRG-OS-000037-GPOS-00015
Rule Version
SLEM-05-653015
Severity
CAT II
CCI(s)
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000154 - Provide the capability to centrally review and analyze audit records from multiple components within the system.
- CCI-000158 - Provide the capability to process, sort, and search audit records for events of interest based on organization-defined audit fields within audit records.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
Weight
10
Fix Recommendation
Enable SLEM 5 auditd service by using the following commands:
> sudo systemctl enable auditd.service
> sudo systemctl start auditd.service
Check Contents
Verify SLEM 5 produces audit records with the following commands:
> systemctl is-active auditd.service
active
> systemctl is-enabled auditd.service
enabled
If the service is not active or not enabled, this is a finding.
Vulnerability Number
V-261411
Documentable
False
Rule Version
SLEM-05-653015
Severity Override Guidance
Verify SLEM 5 produces audit records with the following commands:
> systemctl is-active auditd.service
active
> systemctl is-enabled auditd.service
enabled
If the service is not active or not enabled, this is a finding.
Check Content Reference
M
Target Key
5596