3.5 Retain install.log for 365 or more days

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Archiving and retaining install.log for at least a year is beneficial in the event of an incident as it will allow the user to view the various changes to the system along with the date and time they occurred.

Solution

Perform the following to implement the prescribed state:
Run the following command in Terminal:
sudo vim /etc/asl/com.apple.install
Replace or edit the current setting with a compliant setting
* file /var/log/install.log mode=0640 format=bsd rotate=utc compress file_max=5M ttl=365

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-11

Plugin: Unix

Control ID: 62c063b935da7a409d82aed4e67900799a3c02f9ee91540d8869ed6ad0d1dc26