Check: SOL-11.1-100040
Solaris 11 X86 STIG:
SOL-11.1-100040
(in versions v3 r2 through v1 r10)
Title
The audit system must identify in which zone an event occurred. (Cat III impact)
Discussion
Tracking the specific Solaris zones in the audit trail reduces the time required to determine the cause of a security event.
Check Content
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Determine whether the "zonename" auditing policy is in effect. # pfexec auditconfig -getpolicy | grep active | grep zonename If no output is returned, this is a finding.
Fix Text
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Enable the "zonename" auditing policy. # pfexec auditconfig -setpolicy +zonename
Additional Identifiers
Rule ID: SV-216241r959010_rule
Vulnerability ID: V-216241
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |