SV-268245r1038756_rule
V-268245
SRG-APP-000096-NDM-000226
HYCU-ND-000290
CAT II
10
Log in to the HYCU VM console and load the STIG audit rules by using the following commands:
1. cp /usr/share/audit/sample-rules/10-base-config.rules /usr/share/audit/sample-rules/30-stig.rules /usr/share/audit/sample-rules/31-privileged.rules /usr/share/audit/sample-rules/99-finalize.rules /etc/audit/rules.d/
2. augenrules --load
Check the contents of the "/var/log/audit/audit.log" file.
HYCU also maintains Event (Audit) information in the "HYCU Web UI Events" menu.
Verify the audit log contains records for:
- When (date and time) events occurred.
- Where events occurred.
- The source of the event(s).
- The outcome of the event(s).
- The identity of any individual or process associated with the event(s).
If the audit log is not configured or does not have required contents, this is a finding.
V-268245
False
HYCU-ND-000290
Check the contents of the "/var/log/audit/audit.log" file.
HYCU also maintains Event (Audit) information in the "HYCU Web UI Events" menu.
Verify the audit log contains records for:
- When (date and time) events occurred.
- Where events occurred.
- The source of the event(s).
- The outcome of the event(s).
- The identity of any individual or process associated with the event(s).
If the audit log is not configured or does not have required contents, this is a finding.
M
5660