4.5 Configure Solaris Auditing - audit_flags root = lo,ad,ft,ex,cis:no

Information

NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.

Solution

To enforce this setting, use the command:
# auditconfig -conf
# auditconfig -setflags lo,ad,ft,ex,cis
# auditconfig -setnaflags lo
# auditconfig -setpolicy cnt,argv,zonename
# auditconfig -setplugin audit_binfile active p_minfree=1
# audit -s
# rolemod -K audit_flags=lo,ad,ft,ex,cis:no root
# EDITOR=ed crontab -e root << END_CRON
$ a 0 * * * * /usr/sbin/audit -n .
w q
END_CRON
# chown root:root /var/audit
# chmod 750 /var/audit

See Also

https://workbench.cisecurity.org/files/611

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 64e47d84ecbc3d7a1e45150549e209d2b95c1b0cad318a25bad043204cc7c081