AOSX-11-000305 - The system must provide an immediate real-time alert of all audit failure events requiring real-time alerts.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The audit service must be configured to require a minimum percentage of free disk space in order to run. This ensures that audit will notify the administrator that action is required to free up more disk space for audit logs.

When minfree is set to 25%, security personnel are notified immediately when the storage volume is 75% full and are able to plan for audit record storage capacity expansion.false

Solution

Edit the /etc/security/audit_control file, and change the value for "minfree" to "25". Use the following command to set the "minfree" value to "25%":

/usr/bin/sudo /usr/bin/sed -i.bak 's/.*minfree.*/minfree:25/' /etc/security/audit_control; /usr/bin/sudo /usr/sbin/audit -s

A text editor may also be used to implement the required updates to the /etc/security/audit_control file.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-11_V1R6_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5(1), CAT|II, CCI|CCI-001855, Rule-ID|SV-82005r1_rule, STIG-ID|AOSX-11-000305, Vuln-ID|V-67515

Plugin: Unix

Control ID: d6ac61b7b1c576a3d924878be1b58fb74f019e2c778d883069817a1c9b6bea20