SV-204540r603261_rule
V-204540
SRG-OS-000392-GPOS-00172
RHEL-07-030610
CAT II
10
Configure the operating system to generate audit records when unsuccessful account access events occur.
Add or update the following rule in "/etc/audit/rules.d/audit.rules":
-w /var/run/faillock -p wa -k logins
The audit daemon must be restarted for the changes to take effect.
Verify the operating system generates audit records when unsuccessful account access events occur.
Check the file system rule in "/etc/audit/audit.rules" with the following commands:
# grep -i /var/run/faillock /etc/audit/audit.rules
-w /var/run/faillock -p wa -k logins
If the command does not return any output, this is a finding.
V-204540
False
RHEL-07-030610
Verify the operating system generates audit records when unsuccessful account access events occur.
Check the file system rule in "/etc/audit/audit.rules" with the following commands:
# grep -i /var/run/faillock /etc/audit/audit.rules
-w /var/run/faillock -p wa -k logins
If the command does not return any output, this is a finding.
M
2899