SOL-11.1-010230 - The audit system must be configured to audit account creation - getpolicy

Information

Without auditing, malicious activity cannot be detected.

Solution

The Audit Configuration profile is required. All audit flags must be enabled in a single command.

This action applies to the global zone only. Determine the zone that you are currently securing.

# zonename

If the command output is 'global', this action applies.

For Solaris 11, 11.1, 11.2, and 11.3:
# pfexec auditconfig -setflags cusa,-ps,fd,-fa,fm

For Solaris 11.4 or newer:
# pfexec auditconfig -setflags cusa,-fa,-ex,-ps,fd,fm

Enable the audit policy to collect command line arguments.

# pfexec auditconfig -setpolicy +argv

These changes will not affect users that are currently logged in.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V2R4_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12, CAT|II, CCI|CCI-000018, Rule-ID|SV-216259r603267_rule, STIG-ID|SOL-11.1-010230, STIG-Legacy|SV-60683, STIG-Legacy|V-47807, Vuln-ID|V-216259

Plugin: Unix

Control ID: 2c0a26b0d1d3680737cdbce919a273228eb5e5c349fd6c47a0d64a8d3b8b89de