Check: SRG-OS-000254-GPOS-00095
General Purpose Operating System SRG:
SRG-OS-000254-GPOS-00095
(in versions v2 r7 through v1 r4)
Title
The operating system must initiate session audits at system start-up. (Cat II impact)
Discussion
If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Check Content
Verify the operating system initiates session audits at system start-up. If it does not, this is a finding.
Fix Text
Configure the operating system to initiate session audits at system start-up.
Additional Identifiers
Rule ID: SV-203670r379231_rule
Vulnerability ID: V-203670
Group Title: SRG-OS-000254
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-001464 |
The information system initiates session audits at system start-up. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AU-14 (1) |
System Start-Up |