SOL-11.1-010420 - The operating system must shut down by default upon audit failure (unless availability is an overriding concern)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Continuing to operate a system without auditing working properly can result in undocumented access or system changes.

Solution

The Audit Configuration profile is required.

This action applies to the global zone only. Determine the zone that you are currently securing.

# zonename

If the command output is 'global', this action applies.

Set audit policy to halt and suspend on failure.

# pfexec auditconfig -setpolicy +ahlt
# pfexec auditconfig -setpolicy -cnt

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V2R8_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000140, Rule-ID|SV-216041r603268_rule, STIG-ID|SOL-11.1-010420, STIG-Legacy|SV-60737, STIG-Legacy|V-47863, Vuln-ID|V-216041

Plugin: Unix

Control ID: e3d1598b797dd0347df938bdb126f3673b2a009ee6d5aaaa73f0bfe31b22dafe