AOSX-09-000125 - The operating system must automatically audit account modification.

Information

Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to create a new account or modify an existing one. Auditing of account creation and modification is one method for mitigating this risk. To address access requirements, many operating systems can be integrated with enterprise-level authentication/access/auditing mechanisms that meet or exceed access control policy requirements.

Solution

To make sure the appropriate flags are enabled for auditing, run the following command:

sudo sed -i.bak '/^flags/ s/$/,ad/' /etc/security/audit_control; sudo audit -s

A text editor may also be used to implement the required update to the /etc/security/audit_control file.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, CCI|CCI-001403, Group-ID|V-58289, Rule-ID|SV-72719r1_rule, STIG-ID|AOSX-09-000125

Plugin: Unix

Control ID: 0719d0e58bcf63af03359cbef70389332f973b641407c61b8872354a0031e6f7