Check: GEN002720
VMware ESX 3 Server:
GEN002720
(in version v1 r2)
Title
The audit system must be configured to audit failed attempts to access files and programs. (Cat II impact)
Discussion
If the system is not configured to audit certain activities and write them to an audit log, it is more difficult to detect and track system compromises and damages incurred during a system compromise.
Check Content
Check the audit configuration to determine if failed attempts to access files and programs are audited. If they are not, this is a finding.
Fix Text
Configure the system to audit failed attempts to access files and programs.
Additional Identifiers
Rule ID: SV-814r2_rule
Vulnerability ID: V-814
Group Title: GEN002720
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000126 |
The organization determines that the organization-defined subset of the auditable events defined in AU-2 are to be audited within the information system. |
Controls
Number | Title |
---|---|
AU-2 |
Audit Events |