Information
NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.
Solution
To enforce this setting, edit the /etc/security/audit_event file and add the cis audit class to the following audit events:
AUE_CHROOT
AUE_SETREUID
AUE_SETREGID
AUE_FCHROOT
AUE_PFEXEC
AUE_SETUID
AUE_NICE
AUE_SETGID
AUE_PRIOCNTLSYS
AUE_SETEGID
AUE_SETEUID
AUE_SETPPRIV
AUE_SETSID
AUE_SETPGID