STIGQter STIGQter: STIG Summary: IBM AIX 7.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

AIX audit logs must be rotated daily.

DISA Rule

SV-215256r508663_rule

Vulnerability Number

V-215256

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

AIX7-00-002057

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure a cron job or other automated process to rotate the audit logs on a daily basis.

Check Contents

Check for any "crontab" entries that rotate audit logs:

# crontab -l
30 23 * * * /root/logrotate.sh #Daily log rotation script
If such a cron job is found, this is not a finding.

Otherwise, query the SA.

If there is a process automatically rotating audit logs, this is not a finding.

If the SA manually rotates audit logs, this is a finding.

If the audit output is not archived daily, to tape or disk, this is a finding.

Review the audit log directory.

If more than one file is there, or if the file does not have today's date, this is a finding.

Vulnerability Number

V-215256

Documentable

False

Rule Version

AIX7-00-002057

Severity Override Guidance

Check for any "crontab" entries that rotate audit logs:

# crontab -l
30 23 * * * /root/logrotate.sh #Daily log rotation script
If such a cron job is found, this is not a finding.

Otherwise, query the SA.

If there is a process automatically rotating audit logs, this is not a finding.

If the SA manually rotates audit logs, this is a finding.

If the audit output is not archived daily, to tape or disk, this is a finding.

Review the audit log directory.

If more than one file is there, or if the file does not have today's date, this is a finding.

Check Content Reference

M

Target Key

4012

Comments