Information
Without establishing what type of events occurred, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. Ensuring the 'auditd' service is active ensures audit records generated by the kernel are appropriately recorded.
Additionally, a properly configured audit subsystem ensures that actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
Satisfies: SRG-OS-000062-GPOS-00031, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000051-GPOS-00024, SRG-OS-000054-GPOS-00025, SRG-OS-000122-GPOS-00063, SRG-OS-000254-GPOS-00095, SRG-OS-000255-GPOS-00096, SRG-OS-000337-GPOS-00129, SRG-OS-000348-GPOS-00136, SRG-OS-000349-GPOS-00137, SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140, SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145, SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220
Solution
To enable the auditd service run the following command:
$ sudo systemctl enable --now auditd
Item Details
Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE
References: 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-6(4), 800-53|AU-7(1), 800-53|AU-7a., 800-53|AU-7b., 800-53|AU-8b., 800-53|AU-12(3), 800-53|AU-12a., 800-53|AU-12c., 800-53|AU-14(1), 800-53|CM-5(1), 800-53|MA-4(1)(a), CAT|II, CCI|CCI-000130, CCI|CCI-000131, CCI|CCI-000132, CCI|CCI-000133, CCI|CCI-000134, CCI|CCI-000135, CCI|CCI-000154, CCI|CCI-000158, CCI|CCI-000169, CCI|CCI-000172, CCI|CCI-001464, CCI|CCI-001487, CCI|CCI-001814, CCI|CCI-001875, CCI|CCI-001876, CCI|CCI-001877, CCI|CCI-001878, CCI|CCI-001879, CCI|CCI-001880, CCI|CCI-001881, CCI|CCI-001882, CCI|CCI-001889, CCI|CCI-001914, CCI|CCI-002884, CCI|CCI-003938, CCI|CCI-004188, Rule-ID|SV-258152r1015127_rule, STIG-ID|RHEL-09-653015, Vuln-ID|V-258152
Control ID: 515a2dd67f24c67487c929d725263b39d38f248a632fd6e0d86b6cab45bc000c