OL07-00-030350 - The Oracle Linux operating system must immediately notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when the threshold for the repository maximum audit record storage capacity is reached - at a minimum when the threshold for the repository maximum audit record storage capacity is reached.


If security personnel are not notified immediately when the threshold for the repository maximum audit record storage capacity is reached, they are unable to expand the audit record storage capacity before records are lost.


Configure the operating system to immediately notify the SA and ISSO (at a minimum) when the threshold for the repository maximum audit record storage capacity is reached.

Uncomment or edit the 'action_mail_acct' keyword in '/etc/audit/auditd.conf' and set it to root and any other accounts associated with security personnel.

action_mail_acct = root

See Also


Item Details

Plugin: Unix

Control ID: 481650736ff8a1d856d182523c37d7a68cd106086738e00d1441d20c3138b39f