Check: GEN000000-IRIX00040
IRIX 6.5:
GEN000000-IRIX00040
(in versions v1 r1 through v1 r0.6)
Title
The /etc/security/audit_user file must not define a different auditing level for specific users. (Cat II impact)
Discussion
The sat_select.options file may be used to selectively audit more, or fewer, auditing features for specific individuals. If used this way it could subject the activity to a lawsuit and could cause the loss of valuable auditing data in the case of a system compromise. If an item is audited for one individual (other than for root and administrative users - who have more auditing features) it must be audited for all.
Check Content
Perform: # cat /etc/config/sat_select.options and # sat_select If /etc/config/sat_select.options files has auditing by users, ensure the users defined are audited with the same flags as all users.
Fix Text
Use sat_select to remove specific user configurations differing from the global audit settings.
Additional Identifiers
Rule ID:
Vulnerability ID: V-4353
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000126 |
The organization determines that the organization-defined subset of the auditable events defined in AU-2 are to be audited within the information system. |
Controls
Number | Title |
---|---|
AU-2 |
Audit Events |