SV-227715r603266_rule
V-227715
SRG-OS-000062
GEN002660
CAT II
10
Use /etc/security/bsmconv to enable auditing on the system.
Determine the type of zone that you are currently securing.
# zonename
If the output of "zonename" is "global", then auditing must be enabled.
Determine if auditing is enabled.
# ps -ef |grep auditd
If the auditd process is not found, this is a finding.
If the output of "zonename" is not "global", then the "perzone" policy must be determined.
# auditconfig --getpolicy
audit policies = cnt,perzone
If "perzone" is not listed then this requirement is not applicable. If "perzone" is listed then determine if auditing is enabled.
# ps -ef |grep auditd
If the auditd process is not found, this is a finding.
V-227715
False
GEN002660
Determine the type of zone that you are currently securing.
# zonename
If the output of "zonename" is "global", then auditing must be enabled.
Determine if auditing is enabled.
# ps -ef |grep auditd
If the auditd process is not found, this is a finding.
If the output of "zonename" is not "global", then the "perzone" policy must be determined.
# auditconfig --getpolicy
audit policies = cnt,perzone
If "perzone" is not listed then this requirement is not applicable. If "perzone" is listed then determine if auditing is enabled.
# ps -ef |grep auditd
If the auditd process is not found, this is a finding.
M
4061