GEN000440 - Successful and unsuccessful logins and logouts must be logged - 'unsuccessful logons are being logged'

Information

Monitoring and recording successful and unsuccessful logins assists in tracking unauthorized access to the system. Without this logging, the ability to track unauthorized activity to specific user accounts may be diminished.

Solution

Verify that login logs are handled correctly in the /etc/syslog.conf file. Verify that service startup scripts for syslog and (w/b)tmp (if present) are enabled. NOTE: Also examine the syslog.conf file for any references to remote log hosts if last/lastb produce no results.

# cat /etc/syslog.conf | tr '011' ' ' | tr -s ' ' | sed -e 's/^[ t]*//' | grep -v '^#' | grep "@"

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, CCI|CCI-000126, Rule-ID|SV-27082r1_rule, STIG-ID|GEN000440, Vuln-ID|V-765

Plugin: Unix

Control ID: ba5cfde851a8be00370de567ab801eb90a38a028162ea5a31497f045a8b4ee62