SOL-11.1-010380 - The audit system must alert the System Administrator (SA) if there is any type of audit failure.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Proper alerts to system administrators and Information Assurance (IA) officials of audit failures ensure a timely response to critical system issues.

Solution

The root role is required.

This action applies to the global zone only. Determine the zone that you are currently securing.

# zonename

If the command output is 'global', this action applies.

Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s).

# pfedit /etc/mail/aliases

Insert a line in the form:
audit_warn:user1,user2

Put the updated aliases file into service.
# newaliases

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V2R8_STIG.zip

Item Details

References: CAT|I, CCI|CCI-001858, Rule-ID|SV-219994r854554_rule, STIG-ID|SOL-11.1-010380, STIG-Legacy|SV-60717, STIG-Legacy|V-47843, Vuln-ID|V-219994

Plugin: Unix

Control ID: d2d3e114c6709de92384335cc3fa83f7ea4ece1716681cfe10573404c748e5db