5.18 Enable 'ALL' Audit Option on 'SYS.AUD$'

Information

As the logging of attempts to alter the SYS.AUD$ table can provide forensic evidence of the initiation of a pattern of unauthorized activities, this logging capability should be set according to the needs of the organization.

Solution

Execute the following SQL statement to remediate this setting. AUDIT ALL ON SYS.AUD$ BY ACCESS;

See Also

https://workbench.cisecurity.org/files/601