RHEL-06-000525 - Auditing must be enabled at boot by setting a kernel parameter - BIOS

Information

Each process on the system carries an 'auditable' flag which indicates whether its activities can be audited. Although 'auditd' takes care of enabling this for all processes which launch after it does, adding the kernel argument ensures it is set for every process during boot.

Solution

To ensure all processes can be audited, even those which start prior to the audit daemon, add the argument 'audit=1' to the kernel line in '/boot/grub/grub.conf' or '/boot/efi/EFI/redhat/grub.conf', in the manner below:

kernel /vmlinuz-version ro vga=ext root=/dev/VolGroup00/LogVol00 rhgb quiet audit=1

UEFI systems may prepend '/boot' to the '/vmlinuz-version' argument.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-14(1), 800-53|SI-7(9), CAT|III, CCI|CCI-000169, Rule-ID|SV-218103r505923_rule, STIG-ID|RHEL-06-000525, STIG-Legacy|SV-50238, STIG-Legacy|V-38438, Vuln-ID|V-218103

Plugin: Unix

Control ID: 9f985fdcd27092e87f6eec0dc3034050db3a473d1fd76891330ee78f243ab75d