PHTN-40-000016 The Photon operating system must enable the auditd service.

Information

Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. To that end, the auditd service must be configured to start automatically and be running at all times.

Satisfies: SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000062-GPOS-00031, SRG-OS-000255-GPOS-00096, SRG-OS-000363-GPOS-00150, SRG-OS-000365-GPOS-00152, SRG-OS-000446-GPOS-00200

Solution

At the command line, run the following commands:

# systemctl enable auditd
# systemctl start auditd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y24M08_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-12a., 800-53|CM-3(5), 800-53|SI-6b., CAT|II, CCI|CCI-000132, CCI|CCI-000133, CCI|CCI-000134, CCI|CCI-000135, CCI|CCI-000169, CCI|CCI-001487, CCI|CCI-001744, CCI|CCI-002699, CCI|CCI-003938, Rule-ID|SV-258808r1003628_rule, STIG-ID|PHTN-40-000016, Vuln-ID|V-258808

Plugin: Unix

Control ID: 5fde92be123c103d6d0c3211f3ff155fd89694e506a6c7b299a55cb012a62564