APPL-14-001030 - The macOS system must configure audit capacity warning.

Information

The audit service must be configured to notify the system administrator when the amount of free disk space remaining reaches an organization defined value.

This rule ensures that the system administrator is notified in advance that action is required to free up more disk space for audit logs.

Satisfies: SRG-OS-000046-GPOS-00022,SRG-OS-000343-GPOS-00134

Solution

Configure the macOS system to require a minimum of 25 percent free disk space for audit record storage with the following command:

/usr/bin/sed -i.bak 's/.*minfree.*/minfree:25/' /etc/security/audit_control; /usr/sbin/audit -s

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_14_V1R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5(1), 800-53|AU-5a., CAT|II, CCI|CCI-000139, CCI|CCI-001855, Rule-ID|SV-259468r941026_rule, STIG-ID|APPL-14-001030, Vuln-ID|V-259468

Plugin: Unix

Control ID: 725fed76710e5f3f59d4081d0659de7ac53037a611cfec1e29b087a58895194e