SV-221801r603260_rule
V-221801
SRG-OS-000392-GPOS-00172
OL07-00-030610
CAT II
10
Configure the operating system to generate audit records when unsuccessful account access events occur.
Add or update the following rule in "/etc/audit/rules.d/audit.rules":
-w /var/run/faillock -p wa -k logins
The audit daemon must be restarted for the changes to take effect.
Verify the operating system generates audit records when unsuccessful account access events occur.
Check the file system rule in "/etc/audit/audit.rules" with the following commands:
# grep -i /var/run/faillock /etc/audit/audit.rules
-w /var/run/faillock -p wa -k logins
If the command does not return any output, this is a finding.
V-221801
False
OL07-00-030610
Verify the operating system generates audit records when unsuccessful account access events occur.
Check the file system rule in "/etc/audit/audit.rules" with the following commands:
# grep -i /var/run/faillock /etc/audit/audit.rules
-w /var/run/faillock -p wa -k logins
If the command does not return any output, this is a finding.
M
4089