1.1.16 Ensure separate partition exists for /var/log/audit

Information

The auditing daemon, auditd , stores log data in the /var/log/audit directory.

Solution

For new installations, during installation create a custom partition setup and specify a separate partition for /var/log/audit .
For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-9, 800-53|CM-6, CSCv6|6.3

Plugin: Unix

Control ID: f7fecfd1deaa87b70bac796408d873afa2b4d07e3907d46bef6b7b40cf118ba7