4.1.3 Ensure auditing for processes that start prior to auditd is enabled - /boot/grub/grub.conf

Information

Audit events need to be captured on processes that start up prior to auditd, so that potential malicious activity cannot go undetected.

Solution

For grub based systems edit /boot/grub/grub.conf to include audit=1 on all kernel lines.

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-14, CSCv6|6.2

Plugin: Unix

Control ID: 931cc655ba5bad9fbb94a87ac0178b895c58fdf5a2a427d84dbea393140e3720