GEN002719 - The audit system must alert the SA in the event of an audit processing failure.

Information

An accurate and current audit trail is essential for maintaining
a record of system activity. If the system fails, the SA must be notified and must take prompt
action to correct the problem.

Minimally, the system must log this event and the SA will receive this notification during the
daily system log review. If feasible, active alerting (such as email or paging) should be
employed consistent with the site's established operations management systems and procedures.

Solution

Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s).

# vi /etc/mail/aliases

Put the updated aliases file into service.

# newaliases

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5(1), CAT|III, CCI|CCI-000139, Rule-ID|SV-227724r505926_rule, STIG-ID|GEN002719, STIG-Legacy|SV-40562, STIG-Legacy|V-22374, Vuln-ID|V-227724

Plugin: Unix

Control ID: 40198e45f416597dce17de16a19f340b7c18338104bfa177f4933d21c8ee26bb