8.1.2 Install and Enable auditd Service

Information

Install and turn on the auditd daemon to record system events.

*Rationale*

The capturing of system events provides system administrators with information to allow
them to determine if unauthorized access to their system is occurring.

Solution

Install auditd-# apt-get install auditdIf needed create proper start links for auditd in /etc/rc*.d by running the following command
from each of the relevant directories-# ln -s ../init.d/auditd S37auditdStart links should be created for run levels 2, 3, 4, and 5.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12a., 800-53|AU-12c.

Plugin: Unix

Control ID: 7d93c9aa4c45bde7a557279cf323c2582b6e68cb356dc42f5479a80bb5d2e33a