5.7 Enable system accounting - Check if system accounting '/usr/bin/su' is configured correctly.

Information

System accounting gathers baseline system data (CPU utilization, disk I/O, etc.) every 20 minutes. The data may be accessed with the sar command, or by reviewing the nightly report files named /var/adm/sa/sar*. Once a normal baseline for the system has been established, unauthorized activity (password crackers and other CPU intensive jobs and activity outside of normal usage hours) may be detected due to departures from the normal system performance curve.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 3e74e30b5cd36a93e215b05c62cfd04d4f99b38d0a62290213145f3f066f7983