Check: SRG-OS-000254-GPOS-00095
General Purpose Operating System SRG:
SRG-OS-000254-GPOS-00095
(in versions v3 r1 through v1 r6)
Title
The operating system must initiate session audits at system start-up. (Cat II impact)
Discussion
If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Check Content
Verify the operating system initiates session audits at system start-up. If it does not, this is a finding.
Fix Text
Configure the operating system to initiate session audits at system start-up.
Additional Identifiers
Rule ID: SV-203670r991555_rule
Vulnerability ID: V-203670
Group Title: SRG-OS-000254
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-001464 |
Initiates session audits automatically at system start-up. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
AU-14(1) |
System Start-up |