3.3 Ensure security auditing retention

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The macOS audit capability contains important information to investigate security or operational issues. This resource is only completely useful if it is retained long enough to allow technical staff to find the root cause of anomalies in the records.

Retention can be set to respect both size and longevity. To retain as much as possible under a certain size the recommendation is to use:

expire-after:60D OR 1G

More info in the man page
man audit_control

Rationale:

The audit records need to be retained long enough to be reviewed as necessary.

Solution

Edit the /etc/security/audit_control file so that:

expire-after is at least 60D OR 1G

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CSCv6|6.3

Plugin: Unix

Control ID: 35043bc2678cd915d435bf10b30a8b902443f02974f268a97c45ba727202c9bb