5.2.3.1 Ensure actions as another user are always logged

Information

sudo provides users with temporarily elevated privileges to perform operations, either as the superuser or another user.

Creating an audit log of users with temporary elevated privileges and the operation(s) they performed is essential to reporting. Administrators will want to correlate the events written to the audit trail with the records written to sudo 's log file to verify if unauthorized commands have been executed.

Solution

Create audit rules

Edit the file /etc/security/audit_event and add the flag aa in the line starting with flags: . The file should contain a line similar to:

flags:aa

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-7, 800-53|AU-12, CSCv7|4.9

Plugin: Unix

Control ID: 1631f01c8812ba27e4a841c4dbc9c1b510cc2a016c86308e2593c5b91ad420b5