SV-100165r1_rule
V-89515
SRG-OS-000062-GPOS-00031
VRAU-SL-000205
CAT II
10
Run the following command:
# echo '-a exit,always -F arch=b64 -S sethostname' >> /etc/audit/audit.rules
Or run the following command to implement all logging requirements:
# /etc/dodscript.sh
Check if the system is configured to audit calls to the "sethostname" system call by running the following command:
# grep -w "sethostname" /etc/audit/audit.rules
If the system is configured to audit this activity, it will return at least one line.
If no line is returned, this is a finding.
V-89515
False
VRAU-SL-000205
Check if the system is configured to audit calls to the "sethostname" system call by running the following command:
# grep -w "sethostname" /etc/audit/audit.rules
If the system is configured to audit this activity, it will return at least one line.
If no line is returned, this is a finding.
M
3459