Information
NOTE: Update the value of CIS_AUDIT_CLASS with the appropriate value for the local environment.
Solution
To enforce this setting, edit the /etc/security/audit_event file and add the cis audit class to the following audit events:
 AUE_CHROOT
 AUE_SETREUID
 AUE_SETREGID
 AUE_FCHROOT
 AUE_PFEXEC
 AUE_SETUID
 AUE_NICE
 AUE_SETGID
 AUE_PRIOCNTLSYS
 AUE_SETEGID
 AUE_SETEUID
 AUE_SETPPRIV
 AUE_SETSID
 AUE_SETPGID