OSX00140 - Enable security auditing

Information

Auditing is the capture and maintenance of information about security-related events. Auditing helps determine the causes and the methods used for successful and failed access attempts.

Solution

1. Open a terminal session and edit the /etc/hostconfig file, by using the command (sudo pico /etc/hostconfig).
2. Add the following line to the file- AUDIT=-YES-
3. Save the file.
4. Restart the machine.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, Rule-ID|SV-31333r1_rule, STIG-ID|OSX00140, Vuln-ID|V-25268

Plugin: Unix

Control ID: 28e0697f4dd8d8beb0216e1051fb9ce08d93c93dd3090242a1e3566c95106986