5.2.1.1 Ensure auditd service is enabled

Information

Turn on the auditd daemon to record system events.

Capturing system events provides system administrators with information to determine if unauthorized access to their system has occurred.

Solution

Run the following command to enable auditd :

# service auditd enable
auditd enabled in /etc/rc.conf

Run the following command to start auditd :

# service auditd start

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|SI-5, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: 246927aeb0c1d11b8ce1926fe4ceef538376aaa71fb43fbaee8e2ce580689bb9