4.2 Enable Auditing of Incoming Network Connections - AUE_SOCKCONNECT : cis

Information

NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.

Solution

To enforce this setting, edit the /etc/security/audit_event file and add the cis audit class to the following audit events:
AUE_ACCEPT
AUE_CONNECT
AUE_SOCKACCEPT
AUE_SOCKCONNECT
AUE_inetd_connect

See Also

https://workbench.cisecurity.org/files/611

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 900cc630a6db6359cf9fd00aebca19ab1d28eeac1577f418683d8ea6c659c1f8