SV-99051r1_rule
V-88401
SRG-OS-000062-GPOS-00031
VROM-SL-000195
CAT II
10
Run the following command:
echo '-a exit,always -F arch=b64 -S clock_settime' >> /etc/audit/audit.rules
Or run the following command to implement all logging requirements:
# /etc/dodscript.sh
Check if SLES for vRealize is configured to audit calls to the "clock_settime" system call, run the following command:
# grep -w "clock_settime" /etc/audit/audit.rules
If SLES for vRealize is configured to audit this activity, it will return at least a line containing "-S clock_settime" that also contain "arch=b64". If no line is returned, this is a finding.
V-88401
False
VROM-SL-000195
Check if SLES for vRealize is configured to audit calls to the "clock_settime" system call, run the following command:
# grep -w "clock_settime" /etc/audit/audit.rules
If SLES for vRealize is configured to audit this activity, it will return at least a line containing "-S clock_settime" that also contain "arch=b64". If no line is returned, this is a finding.
M
3461