4.2 Enable Auditing of Incoming Network Connections - AUE_ACCEPT : cis

Information

NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.

Solution

To enforce this setting, edit the /etc/security/audit_event file and add the cis audit class to the following audit events:
AUE_ACCEPT
AUE_CONNECT
AUE_SOCKACCEPT
AUE_SOCKCONNECT
AUE_inetd_connect

See Also

https://workbench.cisecurity.org/files/612

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 06293791d23d92462996feccc37555d09e5147ac3b6870258c64018e6c1a4477