TOSS 5 audit service must be enabled.
DISA Rule
SV-282438r1200294_rule
Vulnerability Number
V-282438
Group Title
SRG-OS-000062-GPOS-00031
Rule Version
TOSS-05-000387
Severity
CAT II
CCI(s)
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-001880 - Provide a report generation capability that supports after-the-fact investigations of security incidents.
- CCI-001881 - Provide an audit reduction capability that does not alter original content or time ordering of audit records.
- CCI-001882 - Provide a report generation capability that does not alter original content or time ordering of audit records.
- CCI-001889 - Record time stamps for audit records that meet organization-defined granularity of time measurement.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-002884 - Log organization-defined audit events for nonlocal maintenance and diagnostic sessions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
To enable the audit service, run the following command:
$ sudo systemctl enable --now auditd
Check Contents
Verify the audit service is configured to produce audit records using the following command:
$ systemctl status auditd.service
auditd.service - Security Auditing Service
Loaded:loaded (/usr/lib/systemd/system/auditd.service; enabled; vendor preset: enabled)
Active: active (running) since Tues 2022-05-24 12:56:56 EST; 4 weeks 0 days ago
If the audit service is not "active" and "running", this is a finding.
Vulnerability Number
V-282438
Documentable
False
Rule Version
TOSS-05-000387
Severity Override Guidance
Verify the audit service is configured to produce audit records using the following command:
$ systemctl status auditd.service
auditd.service - Security Auditing Service
Loaded:loaded (/usr/lib/systemd/system/auditd.service; enabled; vendor preset: enabled)
Active: active (running) since Tues 2022-05-24 12:56:56 EST; 4 weeks 0 days ago
If the audit service is not "active" and "running", this is a finding.
Check Content Reference
M
Target Key
5738