1.1.16 Ensure separate partition exists for /var/log/audit

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The auditing daemon, auditd , stores log data in the /var/log/audit directory.

Solution

For new installations, during installation create a custom partition setup and specify a separate partition for /var/log/audit .
For systems that were previously installed, create a new partition and configure /etc/fstab as appropriate.

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AU-9, 800-53|CM-6, CSCv6|6.3

Plugin: Unix

Control ID: 36e85f74340e855391b893adfa9cfbbe59e6738e5d126809c46654824bad01f3