SV-279562r1192301_rule
V-279562
SRG-OS-000473-GPOS-00218
NXAC-OS-000072
CAT II
10
1. For AOS, configure the audit rules.
$ sudo salt-call state.sls security/CVM/auditCVM
2. For Prism Central, configure the audit rules.
$ sudo salt-call state.sls security/PCVM/auditPCVM
3. For Files, configure the audit rules.
$ sudo salt-call state.sls security/AFS/auditAFS
4. For AHV, configure the audit rules.
$ sudo salt-call state.sls security/KVM/auditKVM
1. Verify Nutanix AOS generates audit records when concurrent logons to the same account occur using the following command.
$ sudo grep dir /etc/security/faillock.conf
# The directory where the user files with the failure records are kept.
dir = /var/log/faillock
2. Using the location of the faillock log file, check that the following calls are being audited by performing the following command to check the file system rules in "/etc/audit/audit.rules".
$ sudo grep -w faillock /etc/audit/audit.rules
-w /var/log/faillock -p wa -k logins
If the commands do not return a line, or the lines are commented out, this is a finding.
V-279562
False
NXAC-OS-000072
1. Verify Nutanix AOS generates audit records when concurrent logons to the same account occur using the following command.
$ sudo grep dir /etc/security/faillock.conf
# The directory where the user files with the failure records are kept.
dir = /var/log/faillock
2. Using the location of the faillock log file, check that the following calls are being audited by performing the following command to check the file system rules in "/etc/audit/audit.rules".
$ sudo grep -w faillock /etc/audit/audit.rules
-w /var/log/faillock -p wa -k logins
If the commands do not return a line, or the lines are commented out, this is a finding.
M
5730