Check: GEN002760
Title
The audit system must be configured to audit all administrative, privileged, and security actions. (Cat II impact)
Discussion
If the system is not configured to audit certain activities and write them to an audit log, it is more difficult to detect and track system compromises and damages incurred during a system compromise.
Check Content
Check the auditing configuration of the system. # sat_select If sat_check_priv is not configured, this is a finding.
Fix Text
# sat_select -on sat_check_priv
Additional Identifiers
Rule ID:
Vulnerability ID: V-816
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000347 |
The organization employs automated mechanisms to support auditing of the enforcement actions. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |