Check: SOL-11.1-010040
Solaris 11 SPARC STIG:
SOL-11.1-010040
(in versions v3 r2 through v3 r1)
Title
The audit system must produce records containing sufficient information to establish the identity of any user/subject associated with the event. (Cat II impact)
Discussion
Enabling the audit system will produce records with accurate time stamps, source, user, and activity information. Without this information malicious activity cannot be accurately tracked.
Check Content
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone to be secured. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report the following, this is a finding. audit condition = auditing
Fix Text
The Audit Control profile is required. This action applies to the global zone only. Determine the zone to be secured. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
Additional Identifiers
Rule ID: SV-216246r986419_rule
Vulnerability ID: V-216246
Group Title: SRG-OS-000255
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001487 |
Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event. |
CCI-004188 |
Monitor the use of maintenance tools that execute with increased privilege. |
Controls
Number | Title |
---|---|
AU-3 |
Content of Audit Records |