Check: GEN002870
Solaris 9 X86 STIG:
GEN002870
(in version v1 r9)
Title
The system must be configured to send audit records to a remote audit server. (Cat III impact)
Discussion
Audit records contain evidence that can be used in the investigation of compromised systems. To prevent this evidence from compromise, it must be sent to a separate system continuously. Methods for sending audit records include, but are not limited to, system audit tools used to send logs directly to another host or through the system's syslog service to another host.
Check Content
Audit records may be sent to a remote server via an NFS mount of the audit directory. Check the "dir" parameter in /etc/security/audit_control. If the directory is on an NFS mount to a remote server, there is no finding. If auditd is saving audit records on a local directory, this is a finding.
Fix Text
Update the /etc/security/audit_control file to save audit records to a remote NFS mount: dir:<remote NFS directory>
Additional Identifiers
Rule ID: SV-40015r1_rule
Vulnerability ID: V-24357
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000136 |
The organization centrally manages the content of audit records generated by organization-defined information system components. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |