AOSX-09-000295 - System must allocate audit record storage capacity to store at least one weeks worth of audit records.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The audit service must be configured to require that records are kept for 7 days or longer before deletion when there is no central audit record storage facility. When expire-after is set to 7d, the audit service will not delete audit logs until the log data is at least 7 days old.

Solution

Edit the /etc/security/audit_control file, and change the value for 'expire-after' to the amount of time audit logs should be kept for the system. Use the following command to set the 'expire-after' value to '7d':

sudo sed -i.bak 's/.*expire-after.*/expire-after:7d/' /etc/security/audit_control; sudo audit -s

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4, CAT|II, CCI|CCI-001849, CSCv6|6.3, Group-ID|V-58321, Rule-ID|SV-72751r1_rule, STIG-ID|AOSX-09-000295

Plugin: Unix

Control ID: e22e426d6345b96c260de03d21c40c8cd83dd30fa85276aeebb2059d03f250a3