UBTU-16-030430 - The audit system must take appropriate action when the network cannot be used to off-load audit records.

Information

Information stored in one location is vulnerable to accidental or incidental deletion or alteration.

Off-loading is a common process in information systems with limited audit storage capacity.

Solution

Configure the Ubuntu operating system to take appropriate action when the network cannot be used to off-load audit records.

Add, edit or uncomment the 'network_failure_action' option in '/etc/audisp/audisp-remote.conf'. Set it to 'syslog', 'single' or 'halt' like the below example:

network_failure_action = single

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_16-04_LTS_V2R3_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-215140r610931_rule, STIG-ID|UBTU-16-030430, STIG-Legacy|SV-90539, STIG-Legacy|V-75859, Vuln-ID|V-215140

Plugin: Unix

Control ID: bf31980734ceb523f7260b44de073b2855e6cf9ebc0f5966b18622797a407dd6