4.1 Create CIS Audit Class

Information

To group a set of related audit events, the Solaris Audit service provides the ability for sites to define their own audit classes that contain just those events that the site wants to audit.

Rationale:

To simplify administration, a CIS specific audit class should be created.

Solution

To create the CIS audit class, edit the /etc/security/audit_class file and add the following entry before the last line of the file:

0x0100000000000000:cis:CIS Solaris Benchmark

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, CSCv7|6.2

Plugin: Unix

Control ID: e28bf6aa24f730d7bbb739b944bd62ef3a3c6f0f7d04c3757b1d43d532df3a84