Check: SOL-11.1-010370
Solaris 11 SPARC STIG:
SOL-11.1-010370
(in versions v3 r2 through v1 r10)
Title
The audit system must alert the SA when the audit storage volume approaches its capacity. (Cat II impact)
Discussion
Filling the audit storage area can result in a denial of service or system outage and can lead to events going undetected.
Check Content
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The root role is required. Verify the presence of an audit_warn entry in /etc/mail/aliases. # /usr/lib/sendmail -bv audit_warn If the response is: audit_warn... User unknown this is a finding. Review the output of the command and verify that the audit_warn alias notifies the appropriate users in this form: audit_warn:user1,user2 If an appropriate user is not listed, this is a finding.
Fix Text
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s). # pfedit /etc/mail/aliases Insert a line in the form: audit_warn:user1,user2 Put the updated aliases file into service. # newaliases
Additional Identifiers
Rule ID: SV-219965r971542_rule
Vulnerability ID: V-219965
Group Title: SRG-OS-000343
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001855 |
Provide a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit log storage volume reaches an organization-defined percentage of repository maximum audit log storage capacity. |
Controls
Number | Title |
---|---|
AU-5(1) |
Audit Storage Capacity |