SV-268244r1211034_rule
V-268244
SRG-APP-000516-NDM-000334
HYCU-ND-000280
CAT II
10
Configure the operating system to use a locally developed list of auditable events by editing "/etc/audit/auditd.conf" files using the following command:
sudo vi /etc/audit/auditd.conf
Add or modify lines to have the required values for the organization.
Log in to the HYCU VM console.
Review the "/etc/audit/auditd.conf" file and verify the settings are in accordance with a locally developed list of auditable events.
If it is not configured in accordance with organizational policies, this is a finding.
Check for the value of the "max_log_file_action" option in "/etc/audit/auditd.conf" with the following command:
sudo grep max_log_file_action /etc/audit/auditd.conf
If the "max_log_file_action" value is not set to "ROTATE", this is a finding.
V-268244
False
HYCU-ND-000280
Log in to the HYCU VM console.
Review the "/etc/audit/auditd.conf" file and verify the settings are in accordance with a locally developed list of auditable events.
If it is not configured in accordance with organizational policies, this is a finding.
Check for the value of the "max_log_file_action" option in "/etc/audit/auditd.conf" with the following command:
sudo grep max_log_file_action /etc/audit/auditd.conf
If the "max_log_file_action" value is not set to "ROTATE", this is a finding.
M
5660